NIST 800-171 · Access Control
Requirement 3.1.15
- SPRS weight
- SPRS weight: 1
- POA&M eligibility
- POA&M-eligible
- Assessment objectives
- 4 assessment objectives
Official requirement text
Authorize remote execution of privileged commands and remote access to security-relevant information.
Assessment objectives
Assessors don’t evaluate the requirement as one sentence; they walk these objectives one by one. Each must be met for the requirement to score.
- 3.1.15[a]privileged commands authorized for remote execution are identified.
- 3.1.15[b]security-relevant information authorized to be accessed remotely is identified.
- 3.1.15[c]the execution of the identified privileged commands via remote access is authorized.
- 3.1.15[d]access to the identified security-relevant information via remote access is authorized.
Inside Valontir, this requirement carries a full plain-English guide: what it asks in normal words, what good looks like in a small shop, the evidence an assessor accepts, the common gaps that cost points, and a plain reading of every assessment objective shown above. See it in a demo.