Remote IdP global admin
Changing MFA policies from home requires PAW + PIM elevation + recorded session — the ‘additional protection’ AC-17(7) sought, implemented via modern controls.
AC-17(7) historically called for additional protection for remote access to security functions. In NIST SP 800-53 Rev. 5 the enhancement is withdrawn (capabilities covered through other controls such as AC-17(4), AC-6, IA-2, and related). Healthcare organizations should still add stronger safeguards when security-relevant functions — IdP admin, EHR security workbench, firewall, SIEM — are reachable remotely, and document the Rev. 5 mapping so SSP rows are not left empty.
Apply heightened protections whenever security functions that guard ePHI are exercised remotely, while noting AC-17(7) withdrawal and inheritance to surviving controls.
How this control shows up in healthcare and HIPAA-covered environments.
Changing MFA policies from home requires PAW + PIM elevation + recorded session — the ‘additional protection’ AC-17(7) sought, implemented via modern controls.
Role design changes blocked from general VPN; only via privileged VDI with clipboard limits.
Network security engineers use PAM to the management plane; standing any-VPN admin to firewalls is removed.
Withdrawn status is not a free pass. Auditors still expect additional protection for remote security administration affecting ePHI — show the inherited control set.
How this NIST control supports HIPAA Security Rule expectations.
No — it is withdrawn. Implement equivalent protections through related controls and document the mapping.
PAW, PAM, phishing-resistant MFA, tighter authorization, monitoring, and shorter sessions for remote security functions.
No. The risk remains; only the control number changed.
Related controls that commonly accompany AC-17(7).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.