AC-17(7) Access Control

Additional Protection for Security Function Access

Critical Risk Complex High Cost

AC-17(7) historically called for additional protection for remote access to security functions. In NIST SP 800-53 Rev. 5 the enhancement is withdrawn (capabilities covered through other controls such as AC-17(4), AC-6, IA-2, and related). Healthcare organizations should still add stronger safeguards when security-relevant functions — IdP admin, EHR security workbench, firewall, SIEM — are reachable remotely, and document the Rev. 5 mapping so SSP rows are not left empty.

Control Objective

Apply heightened protections whenever security functions that guard ePHI are exercised remotely, while noting AC-17(7) withdrawal and inheritance to surviving controls.

Implementation Guidance

  1. SSP note: AC-17(7) withdrawn; inherit additional remote protections via AC-17(4), AC-6, IA-2(1)/phishing-resistant MFA, PAW, and PAM.
  2. Require dedicated privileged accounts and managed admin workstations for remote security admin.
  3. Prefer no direct remote access to security consoles — use PAM brokers with recording.
  4. Step-up authentication and shorter session lifetimes for security-function remote use.
  5. Geo/device conditional access on IdP and cloud security portals.
  6. Dual authorization for especially sensitive remote security changes where feasible (AC-3(2)).
  7. Continuous monitoring of remote security-admin sessions (AC-17(1)/SI-4).
  8. Keep operational runbooks even if the enhancement ID is withdrawn.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Remote IdP global admin

Changing MFA policies from home requires PAW + PIM elevation + recorded session — the ‘additional protection’ AC-17(7) sought, implemented via modern controls.

EHR security workbench offsite

Role design changes blocked from general VPN; only via privileged VDI with clipboard limits.

Firewall rule changes after hours

Network security engineers use PAM to the management plane; standing any-VPN admin to firewalls is removed.

Best Practices

  • Document withdrawal and control inheritance clearly.
  • Never equate withdrawn with ‘do nothing.’
  • PAW + PAM for remote security functions.
  • Phishing-resistant MFA.
  • Session recording and short TTLs.
  • Align with AC-17(4) privileged remote rules.

Common Gaps & Violations

  • Marking AC-17(7) N/A and allowing casual remote Domain Admin.
  • Security consoles on the general employee VPN pool.
  • No extra authentication for cloud Owner roles.
  • Shared security-admin passwords for remote after-hours work.
  • Missing SSP crosswalk for withdrawn enhancement.

Required Documentation

  • SSP mapping: AC-17(7) withdrawn → implementing controls
  • Privileged remote security-function procedures
  • PAW/PAM requirements for security admins
  • Conditional access policies for admin portals
  • Sample recorded privileged sessions

How to Test & Validate

  1. Confirm SSP withdrawal language and mapped controls.
  2. Attempt security-console access from a standard remote session; expect deny.
  3. Verify MFA/PIM for remote security roles.
  4. Review who has remote rights to IdP/EHR security.
  5. Validate session recording on a test admin change.

Audit Considerations

Withdrawn status is not a free pass. Auditors still expect additional protection for remote security administration affecting ePHI — show the inherited control set.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — security functions that manage ePHI access need strongest remote limits.
  • 164.312(d) Person or Entity Authentication — stronger authentication for remote security admin.
  • 164.308(a)(3) Workforce Security — supervise workforce performing security functions remotely.
  • 164.312(b) Audit Controls — remote security-function use must be logged.

Compliance Tips

  • Keep a withdrawn-enhancements appendix in the SSP with ‘how we still meet the intent.’
  • Prioritize IdP, EHR security, and backup-admin remote paths.
  • Tabletop a compromised remote security-admin scenario.

Frequently Asked Questions

Is AC-17(7) still active in Rev. 5?

No — it is withdrawn. Implement equivalent protections through related controls and document the mapping.

What ‘additional protections’ should we keep?

PAW, PAM, phishing-resistant MFA, tighter authorization, monitoring, and shorter sessions for remote security functions.

Does withdrawal mean remote security admin is fine on any laptop?

No. The risk remains; only the control number changed.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-17(7) [Withdrawn]
  • Related controls: AC-17(4), AC-6, IA-2, AU-2, SI-4

Need Help Implementing AC-17(7)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.