Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
3.1.15OFFICIAL STATEMENT BELOWDERIVED REQUIREMENTPENDING NIST SME REVIEW

3.1.15Privileged remote access authorization

3.1 Access Control · NIST SP 800-171 Rev. 2 · The heading label is this site's navigational shorthand; the official language is the statement below.

Official requirement statement (verbatim)

Authorize remote execution of privileged commands and remote access to security-relevant information.

NIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

Doing administrative work remotely — running privileged commands, touching security configuration — requires explicit authorization, not just a working VPN login. You decide which privileged operations may happen remotely, who may perform them, and from where, and you write that decision down.

Across revisions

Withdrawn as a standalone slot in Rev. 3 (03.01.15); authorization of remote privileged commands is carried inside the consolidated Remote Access requirement, 03.01.12.

Mapped practices

Brilliant at the Basics practices that support this requirement

Partial implementation supportModerate confidence

Why: Vendor sessions provisioned per engagement, time-bound, and supervised or recorded are how remote execution of privileged commands gets authorized in practice — remote OT work is almost always privileged work, so the practice's brokering discipline lands directly on this requirement's subject.

What this does not claim: Brokering and recording sessions is not the same as the written authorization the requirement centers on: which privileged operations may be performed remotely, by whom, must still be documented as a deliberate decision. The requirement also spans remote privileged work across the whole boundary — IT servers, identity infrastructure, security tooling — which this OT-focused practice does not reach.

Practice-side activities
  • Document which remote privileged operations are permitted per vendor engagement and who may perform them
  • Supervise or record privileged remote sessions where warranted, with the records retained
Evidence this produces
  • Per-engagement authorization records for vendor remote work
  • Session recordings or supervision logs for privileged remote sessions

Where this holds: Holds only where OT systems fall within the organization's CUI boundary.

Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Document which privileged commands and security-relevant access are permitted remotely and for whom; the authorization record is the requirement's core artifact.
  • Restrict remote administrative work to designated accounts and hardened paths — a jump host or privileged access workstation — rather than any laptop on the VPN.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • The written authorization naming permitted remote privileged operations and holders
  • Configuration restricting remote administrative access to the designated accounts and paths
  • Session logs or recordings for remote privileged work where the tooling supports it

Suggested owners, derived from the mapped practices and artifacts: OT / network administrator. Ownership is a named person in your organization, not a role on a website.

Artifacts

Templates and worksheets with a mapped relationship

No artifact in the library names this requirement yet. The library index groups everything by category and practice.

The other revision

Where this lands in Rev. 3

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated