AC-17(8) Access Control

Disable Nonsecure Network Protocols

High Risk Moderate Medium Cost

AC-17(8) historically required disabling nonsecure remote access protocols (e.g., cleartext or obsolete remote services). In Rev. 5 it is withdrawn and incorporated into CM-7 (Least Functionality). Healthcare IT must still remove Telnet, unencrypted remote admin, legacy SSL VPN ciphers, insecure management protocols on clinical devices, and similar paths that could expose ePHI credentials or sessions — tracked under CM-7 with AC-17 policy context.

Control Objective

Ensure nonsecure protocols usable for remote access to ePHI environments are disabled or blocked, documenting Rev. 5 inheritance from AC-17(8) into CM-7.

Implementation Guidance

  1. SSP note: AC-17(8) withdrawn into CM-7; maintain a prohibited remote-protocol list.
  2. Block Telnet, cleartext FTP admin, SNMPv1/v2c where abused for remote management, and outdated VPN protocols at edge and host.
  3. Require SSH/TLS equivalents for device management on clinical and biomed networks.
  4. Disable unused remote services on EHR, PACS, and interface engines.
  5. Scan for protocol debt after mergers and clinic acquisitions.
  6. Exception process with compensating controls and expiry for legacy medical devices.
  7. Align VPN cipher disablement with AC-17(2).
  8. Verify cloud and SaaS admin endpoints reject weak TLS.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Telnet to legacy lab analyzer gateway

Cleartext remote management replaced with SSH jump access under CM-7/AC-17(8) intent; credentials no longer traverse the clinic VLAN in the clear.

PPTP VPN remnant

Old PPTP concentrator still online for one specialty clinic. Decommission forces modern VPN — nonsecure remote protocol removed.

Unencrypted remote desktop

Internal RDP without NLA/TLS to a charting server is hardened or brokered via gateway.

Best Practices

  • Maintain prohibited protocol list under CM-7.
  • Scan acquisitions quickly.
  • Time-box medical-device exceptions.
  • Pair with network segmentation.
  • Document withdrawal mapping in SSP.
  • Retest after appliance upgrades that re-enable defaults.

Common Gaps & Violations

  • Closing AC-17(8) as N/A with Telnet still on clinical switches.
  • Permanent exceptions for ‘the ultrasound that only speaks FTP.’
  • Weak TLS re-enabled after VPN upgrade.
  • No CM-7 baseline for remote services.
  • Biomed VLAN unmanaged for cleartext admin protocols.

Required Documentation

  • SSP mapping: AC-17(8) → CM-7
  • Prohibited/nonsecure protocol standard
  • Hardening baselines for remote services
  • Exception register for legacy clinical devices
  • Scan results showing protocol posture

How to Test & Validate

  1. Verify SSP inheritance language.
  2. Port/protocol scan critical ePHI hosts for Telnet/cleartext admin.
  3. Confirm VPN rejects obsolete protocols.
  4. Review exception list currency.
  5. Spot-check biomed device management protocols.

Audit Considerations

Assessors may still ask about AC-17(8). Show CM-7 least-functionality evidence that nonsecure remote protocols are disabled in ePHI environments.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(e) Transmission Security — cleartext remote protocols undermine transmission protections.
  • 164.312(a)(1) Access Control — insecure remote services expand unauthorized access risk.
  • 164.308(a)(1) Risk Analysis — legacy protocols on clinical devices are known risks.
  • 164.308(a)(5) Awareness and Training — admins need guidance not to re-enable insecure management.

Compliance Tips

  • Put protocol exceptions on the risk register with residual risk rating.
  • Combine CM-7 blacklists with firewall deny rules.
  • Include protocol checks in clinic acquisition checklists.

Frequently Asked Questions

Where did AC-17(8) go in Rev. 5?

Withdrawn and incorporated into CM-7 Least Functionality.

Do medical devices get a free pass?

No — document exceptions, segment, and compensate; plan replacement when vendors lack secure management.

Is disabling enough if monitoring exists?

Prefer disable. Monitoring does not encrypt cleartext Telnet credentials.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-17(8) [Withdrawn: Incorporated into CM-7]
  • Related controls: CM-7, AC-17, AC-17(2), SC-8, SC-7

Need Help Implementing AC-17(8)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.