Partial implementation supportModerate confidence
Why: Controlling remote access sessions begins with who can open one, and the practice puts phishing-resistant MFA on remote entry points first — its stated priority order — closing the credential-theft path that makes remote access the leading intrusion vector.
What this does not claim: Authentication strength addresses the control half for the sanctioned pathways only. The requirement's monitoring half — session logging, visibility, someone reviewing — is not produced by MFA, and unauthorized remote pathways that bypass the identity provider entirely must be found and closed by separate work.
Practice-side activities- Enforce phishing-resistant MFA on VPN, remote desktop gateways, and remote portals before the general workforce rollout
- Block legacy authentication on remote entry points so no path accepts a bare password
Evidence this produces- Enforcement policy exports scoped to remote access applications
- Remote sign-in logs showing MFA required across sampled sessions
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06
Partial implementation supportModerate confidence
Why: Brokered, logged, time-bound remote access is this requirement's substance enacted for OT: every vendor and off-site pathway inventoried, sessions arriving through a monitored broker, and session records reviewed.
What this does not claim: This mapping applies only to OT components that process, store, or transmit CUI, or that provide security protection for those components — organizational scoping determines applicability. The practice also covers OT and vendor pathways only; workforce remote access into the corporate IT estate, which the requirement equally covers, is outside its scope.
Practice-side activities- Inventory every remote and vendor pathway into OT, including modems and cellular links, and disable the unowned ones
- Route remaining pathways through a brokered jump host with session logging
- Enable access per session or window and disable it afterward
Evidence this produces- The remote-pathway inventory with owner and business reason per path
- Broker session logs and the review records against them
Where this holds: Holds only where OT systems fall within the organization's CUI boundary.
Review status: Technical review complete · Reviewed by inDirectIT practitioner review — CUI security and NIST SP 800-171 engineering · updated 2026-08-06