A company has multiple sites with employees at each site that must access the company's CUI network from their remote locations. The company has set up a single access point for all employees to access the network. What is the MOST significant factor in determining whether the security on this single access point is adequate?
Applicable Requirement: AC.L2-3.1.12 and AC.L2-3.1.14 --- ''Monitor and control remote access sessions'' and ''Route remote access through managed access control points.''
Why A is Correct: For a single centralized access point, the most critical control is that remote access sessions are properly secured and monitored to prevent unauthorized access to CUI systems. This ensures both confidentiality and integrity of remote connections.
Why Other Options Are Insufficient:
B: Physical access controls protect on-site systems but do not address remote connection security.
C: Documentation alone is not sufficient; actual monitoring and security enforcement are required.
D: Notification procedures relate to incident handling, not adequacy of access point security.
Reference (CCA Official Sources):
NIST SP 800-171 Rev. 2 --- AC.L2-3.1.12, AC.L2-3.1.14
NIST SP 800-171A --- Remote Access Assessment Objectives
CMMC Assessment Guide -- Level 2, Remote Access Guidance
Lavonda
4 days agoAllene
9 days agoJolanda
14 days ago