AC-17(5) Access Control

Monitoring for Unauthorized Connections

High Risk Moderate Medium Cost

AC-17(5) historically required monitoring for unauthorized remote connections to the system. In NIST SP 800-53 Rev. 5 this enhancement is withdrawn and incorporated into SI-4 (System Monitoring). Healthcare programs should still detect rogue VPN concentrators, unexpected inbound remote ports, unauthorized remote-support agents, and unapproved cloud admin paths that could reach ePHI — implementing that capability under SI-4 while preserving AC-17 remote-access policy context.

Control Objective

Detect unauthorized remote connection methods and attempts involving ePHI environments, recognizing Rev. 5 maps this outcome primarily to SI-4 while operational need remains.

Implementation Guidance

  1. Note in the SSP: AC-17(5) withdrawn into SI-4; cite SI-4 use cases covering unauthorized remote connections.
  2. Alert on new listeners (RDP/SSH/VNC) on clinical servers and unexpected outbound remote-support callbacks.
  3. Compare active remote sessions to the approved AC-17 method inventory.
  4. Watch DNS/firewall for connections to consumer remote-access domains from ePHI endpoints.
  5. Include wireless rogue bridges that create unintended remote paths (ties to AC-18).
  6. Hunt after phishing for new remote-access malware beacons.
  7. Retain evidence of detections/responses for audits still referencing AC-17(5) language.
  8. Cross-train SOC that ‘unauthorized remote connection’ is a named SI-4 detection family.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Rogue remote agent on clinic PC

EDR finds an unapproved remote-support install calling home. Treated as SI-4/AC-17 unauthorized remote path; host isolated before ePHI access.

Unexpected RDP exposure

External scan finds RDP open on a forgotten imaging PC. Monitoring and edge controls close the unauthorized remote connection path.

Shadow cloud tunnel

A department spins up a personal reverse tunnel into a billing share. Firewall anomalies flag it as unauthorized remote connectivity.

Best Practices

  • Document withdrawal mapping AC-17(5) → SI-4 in control inheritance.
  • Keep unauthorized-remote detections funded and tested.
  • Reconcile sessions to approved methods.
  • Include consumer remote-tool IOCs.
  • Pair with CM-7 / application control.
  • Do not drop the operational control just because the enhancement ID withdrew.

Common Gaps & Violations

  • Marking AC-17(5) N/A with no SI-4 coverage for remote threats.
  • No detection for unauthorized remote-support software.
  • Ignoring outbound tunnels from clinical VLANs.
  • Inventory of approved remote methods outdated.
  • Findings closed as ‘withdrawn’ without compensating SI-4 evidence.

Required Documentation

  • SSP note: AC-17(5) withdrawn into SI-4
  • SI-4 use cases for unauthorized remote connections
  • Approved remote methods inventory
  • Sample alerts and incident tickets
  • Edge scan / exposure reports

How to Test & Validate

  1. Verify SSP inheritance language AC-17(5) → SI-4.
  2. Simulate unauthorized remote tool callback in a lab VLAN; confirm detect.
  3. Review edge for unexpected remote ports.
  4. Sample endpoints for unapproved remote-support software.
  5. Confirm SOC runbooks reference unauthorized remote connections.

Audit Considerations

If an assessor still cites AC-17(5), show Rev. 5 withdrawal into SI-4 plus living detections for unauthorized remote paths to ePHI — not a blank N/A.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(1)(ii)(D) Information System Activity Review — review of remote connection activity.
  • 164.312(b) Audit Controls — record and examine activity including connection attempts.
  • 164.308(a)(6) Security Incident Procedures — unauthorized remote access is an incident class.
  • 164.312(a)(1) Access Control — prevent unauthorized remote entry to ePHI systems.

Compliance Tips

  • Keep a crosswalk row: AC-17(5) withdrawn → SI-4 detections listed.
  • Continue quarterly hunts for shadow remote tools.
  • Mention telehealth and BA remote paths in SI-4 scope.

Frequently Asked Questions

Is AC-17(5) still selectable in Rev. 5 baselines?

It is withdrawn/incorporated into SI-4. Implement the capability under SI-4 and note the mapping.

Why keep content for a withdrawn enhancement?

Assessors, older SSPs, and contracts may still reference AC-17(5); operational risk of unauthorized remote access did not disappear.

Does AC-17(1) replace AC-17(5)?

AC-17(1) monitors/controls authorized remote methods; unauthorized connection detection is broader and lives primarily in SI-4.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-17(5) [Withdrawn: Incorporated into SI-4]
  • Related controls: SI-4, AC-17, AC-17(1), CM-7, IR-4

Need Help Implementing AC-17(5)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.