AC.2.013 Monitor and control remote access sessions.

CMMC Practice AC.2.013: Monitor and control remote access sessions.

Links to Publicly Available Resources

CMMC CLARIFICATION (Ref CMMC – Appendix B)
Remote access connections pass through untrusted networks and should therefore not be trusted without proper security controls in place. All remote access should implement approved encryption. This ensures the confidentiality of the data. Check connections to ensure that only authorized users and devices are connecting. Monitoring may include tracking who is accessing the network remotely and what files they are accessing during the remote session.