Browse 1,193 controls and enhancements across 20 security and privacy families. Use the GovRAMP crosswalk to locate controls referenced by Security Snapshot, Core, and Moderate.
A shared catalog supports common-control planning; designation as a common, hybrid, or system-specific control depends on your organization’s implementation and inheritance decisions.
Sources and crosswalk scope
NIST OSCAL content 5.1.1+u4, retrieved 2026-09-18. GovRAMP Snapshot v1.4 and Core selection from Moderate v1.06 reference the December 2020 Rev. 5 text. Mappings establish exact identifier correspondence, not identical requirements, inherited implementation, or GovRAMP authorization. GovRAMP parameters and additional requirements remain authoritative for each program. Full Moderate, High, and other programs are not mapped here. Withdrawn controls are retained for reference.
Official pinned NIST sourceSHA-256: 81cf2de45ede9aef3de7ce09d65ea9d32f662c483bbf916f6e346292b22f7763
Access Control · Base control
AC-17 · Remote Access
Control statement and discussion
NIST control statement
a. Establish and document usage restrictions, configuration/connection requirements, and implementation guidance for each type of remote access allowed; and
b. Authorize each type of remote access to the system prior to allowing such connections.
Discussion
Remote access is access to organizational systems (or processes acting on behalf of users) that communicate through external networks such as the Internet. Types of remote access include dial-up, broadband, and wireless. Organizations use encrypted virtual private networks (VPNs) to enhance confidentiality and integrity for remote connections. The use of encrypted VPNs provides sufficient assurance to the organization that it can effectively treat such connections as internal networks if the cryptographic mechanisms used are implemented in accordance with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. Still, VPN connections traverse external networks, and the encrypted VPN does not enhance the availability of remote connections. VPNs with encrypted tunnels can also affect the ability to adequately monitor network communications traffic for malicious code. Remote access controls apply to systems other than public web servers or systems designed for public access. Authorization of each remote access type addresses authorization prior to allowing remote access without specifying the specific formats for such authorization. While organizations may use information exchange and system connection security agreements to manage remote access connections to other systems, such agreements are addressed as part of [CA-3](#ca-3) . Enforcing access restrictions for remote access is addressed via [AC-3](#ac-3).
GovRAMP crosswalk
- GovRAMP Security Snapshot Readiness · AC-17 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Core Readiness — 60 Controls · AC-17 — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · AC-17 — Direct NIST identifier reference. GovRAMP source matrix
Access Control · Enhancement
AC-17(1) · Monitoring and Control
View parent controlControl statement and discussion
NIST control statement
Employ automated mechanisms to monitor and control remote access methods.
Discussion
Monitoring and control of remote access methods allows organizations to detect attacks and help ensure compliance with remote access policies by auditing the connection activities of remote users on a variety of system components, including servers, notebook computers, workstations, smart phones, and tablets. Audit logging for remote access is enforced by [AU-2](#au-2) . Audit events are defined in [AU-2a](#au-2_smt.a).
GovRAMP crosswalk
- GovRAMP Moderate Readiness · AC-17 (1) — Direct NIST identifier reference. GovRAMP source matrix
Access Control · Enhancement
AC-17(2) · Protection of Confidentiality and Integrity Using Encryption
View parent controlControl statement and discussion
NIST control statement
Implement cryptographic mechanisms to protect the confidentiality and integrity of remote access sessions.
Discussion
Virtual private networks can be used to protect the confidentiality and integrity of remote access sessions. Transport Layer Security (TLS) is an example of a cryptographic protocol that provides end-to-end communications security over networks and is used for Internet communications and online transactions.
GovRAMP crosswalk
- GovRAMP Security Snapshot Readiness · AC-17 (2) — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Core Readiness — 60 Controls · AC-17 (2) — Direct NIST identifier reference. GovRAMP source matrix
- GovRAMP Moderate Readiness · AC-17 (2) — Direct NIST identifier reference. GovRAMP source matrix
Access Control · Enhancement
AC-17(3) · Managed Access Control Points
View parent controlControl statement and discussion
NIST control statement
Route remote accesses through authorized and managed network access control points.
Discussion
Organizations consider the Trusted Internet Connections (TIC) initiative [DHS TIC](#4f42ee6e-86cc-403b-a51f-76c2b4f81b54) requirements for external network connections since limiting the number of access control points for remote access reduces attack surfaces.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · AC-17 (3) — Direct NIST identifier reference. GovRAMP source matrix
Access Control · Enhancement
AC-17(4) · Privileged Commands and Access
View parent controlControl statement and discussion
NIST control statement
(a) Authorize the execution of privileged commands and access to security-relevant information via remote access only in a format that provides assessable evidence and for the following needs: [Assignment: organization-defined needs] ; and
(b) Document the rationale for remote access in the security plan for the system.
Discussion
Remote access to systems represents a significant potential vulnerability that can be exploited by adversaries. As such, restricting the execution of privileged commands and access to security-relevant information via remote access reduces the exposure of the organization and the susceptibility to threats by adversaries to the remote access capability.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · AC-17 (4) — Direct NIST identifier reference. GovRAMP source matrix
Access Control · Enhancement
AC-17(6) · Protection of Mechanism Information
View parent controlControl statement and discussion
NIST control statement
Protect information about remote access mechanisms from unauthorized use and disclosure.
Discussion
Remote access to organizational information by non-organizational entities can increase the risk of unauthorized use and disclosure about remote access mechanisms. The organization considers including remote access requirements in the information exchange agreements with other organizations, as applicable. Remote access requirements can also be included in rules of behavior (see [PL-4](#pl-4) ) and access agreements (see [PS-6](#ps-6)).
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Access Control · Enhancement
AC-17(9) · Disconnect or Disable Access
View parent controlControl statement and discussion
NIST control statement
Provide the capability to disconnect or disable remote access to the system within [Assignment: time period].
Discussion
The speed of system disconnect or disablement varies based on the criticality of missions or business functions and the need to eliminate immediate or future remote access to systems.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Access Control · Enhancement
AC-17(10) · Authenticate Remote Commands
View parent controlControl statement and discussion
NIST control statement
Implement [Assignment: mechanisms] to authenticate [Assignment: remote commands].
Discussion
Authenticating remote commands protects against unauthorized commands and the replay of authorized commands. The ability to authenticate remote commands is important for remote systems for which loss, malfunction, misdirection, or exploitation would have immediate or serious consequences, such as injury, death, property damage, loss of high value assets, failure of mission or business functions, or compromise of classified or controlled unclassified information. Authentication mechanisms for remote commands ensure that systems accept and execute commands in the order intended, execute only authorized commands, and reject unauthorized commands. Cryptographic mechanisms can be used, for example, to authenticate remote commands.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Access Control · Base control
AC-18 · Wireless Access
Control statement and discussion
NIST control statement
a. Establish configuration requirements, connection requirements, and implementation guidance for each type of wireless access; and
b. Authorize each type of wireless access to the system prior to allowing such connections.
Discussion
Wireless technologies include microwave, packet radio (ultra-high frequency or very high frequency), 802.11x, and Bluetooth. Wireless networks use authentication protocols that provide authenticator protection and mutual authentication.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · AC-18 — Direct NIST identifier reference. GovRAMP source matrix
Access Control · Enhancement
AC-18(1) · Authentication and Encryption
View parent controlControl statement and discussion
NIST control statement
Protect wireless access to the system using authentication of [Selection (one-or-more): users; devices] and encryption.
Discussion
Wireless networking capabilities represent a significant potential vulnerability that can be exploited by adversaries. To protect systems with wireless access points, strong authentication of users and devices along with strong encryption can reduce susceptibility to threats by adversaries involving wireless technologies.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · AC-18 (1) — Direct NIST identifier reference. GovRAMP source matrix
Access Control · Enhancement
AC-18(3) · Disable Wireless Networking
View parent controlControl statement and discussion
NIST control statement
Disable, when not intended for use, wireless networking capabilities embedded within system components prior to issuance and deployment.
Discussion
Wireless networking capabilities that are embedded within system components represent a significant potential vulnerability that can be exploited by adversaries. Disabling wireless capabilities when not needed for essential organizational missions or functions can reduce susceptibility to threats by adversaries involving wireless technologies.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · AC-18 (3) — Direct NIST identifier reference. GovRAMP source matrix
Access Control · Enhancement
AC-18(4) · Restrict Configurations by Users
View parent controlControl statement and discussion
NIST control statement
Identify and explicitly authorize users allowed to independently configure wireless networking capabilities.
Discussion
Organizational authorizations to allow selected users to configure wireless networking capabilities are enforced, in part, by the access enforcement mechanisms employed within organizational systems.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Access Control · Enhancement
AC-18(5) · Antennas and Transmission Power Levels
View parent controlControl statement and discussion
NIST control statement
Select radio antennas and calibrate transmission power levels to reduce the probability that signals from wireless access points can be received outside of organization-controlled boundaries.
Discussion
Actions that may be taken to limit unauthorized use of wireless communications outside of organization-controlled boundaries include reducing the power of wireless transmissions so that the transmissions are less likely to emit a signal that can be captured outside of the physical perimeters of the organization, employing measures such as emissions security to control wireless emanations, and using directional or beamforming antennas that reduce the likelihood that unintended receivers will be able to intercept signals. Prior to taking such mitigating actions, organizations can conduct periodic wireless surveys to understand the radio frequency profile of organizational systems as well as other systems that may be operating in the area.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Access Control · Base control
AC-19 · Access Control for Mobile Devices
Control statement and discussion
NIST control statement
a. Establish configuration requirements, connection requirements, and implementation guidance for organization-controlled mobile devices, to include when such devices are outside of controlled areas; and
b. Authorize the connection of mobile devices to organizational systems.
Discussion
A mobile device is a computing device that has a small form factor such that it can easily be carried by a single individual; is designed to operate without a physical connection; possesses local, non-removable or removable data storage; and includes a self-contained power source. Mobile device functionality may also include voice communication capabilities, on-board sensors that allow the device to capture information, and/or built-in features for synchronizing local data with remote locations. Examples include smart phones and tablets. Mobile devices are typically associated with a single individual. The processing, storage, and transmission capability of the mobile device may be comparable to or merely a subset of notebook/desktop systems, depending on the nature and intended purpose of the device. Protection and control of mobile devices is behavior or policy-based and requires users to take physical action to protect and control such devices when outside of controlled areas. Controlled areas are spaces for which organizations provide physical or procedural controls to meet the requirements established for protecting information and systems.
Due to the large variety of mobile devices with different characteristics and capabilities, organizational restrictions may vary for the different classes or types of such devices. Usage restrictions and specific implementation guidance for mobile devices include configuration management, device identification and authentication, implementation of mandatory protective software, scanning devices for malicious code, updating virus protection software, scanning for critical software updates and patches, conducting primary operating system (and possibly other resident software) integrity checks, and disabling unnecessary hardware.
Usage restrictions and authorization to connect may vary among organizational systems. For example, the organization may authorize the connection of mobile devices to its network and impose a set of usage restrictions, while a system owner may withhold authorization for mobile device connection to specific applications or impose additional usage restrictions before allowing mobile device connections to a system. Adequate security for mobile devices goes beyond the requirements specified in [AC-19](#ac-19) . Many safeguards for mobile devices are reflected in other controls. [AC-20](#ac-20) addresses mobile devices that are not organization-controlled.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · AC-19 — Direct NIST identifier reference. GovRAMP source matrix
Access Control · Enhancement
AC-19(4) · Restrictions for Classified Information
View parent controlControl statement and discussion
NIST control statement
(a) Prohibit the use of unclassified mobile devices in facilities containing systems processing, storing, or transmitting classified information unless specifically permitted by the authorizing official; and
(b) Enforce the following restrictions on individuals permitted by the authorizing official to use unclassified mobile devices in facilities containing systems processing, storing, or transmitting classified information:
(1) Connection of unclassified mobile devices to classified systems is prohibited;
(2) Connection of unclassified mobile devices to unclassified systems requires approval from the authorizing official;
(3) Use of internal or external modems or wireless interfaces within the unclassified mobile devices is prohibited; and
(4) Unclassified mobile devices and the information stored on those devices are subject to random reviews and inspections by [Assignment: security officials] , and if classified information is found, the incident handling policy is followed.
(c) Restrict the connection of classified mobile devices to classified systems in accordance with [Assignment: security policies].
Discussion
None.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Access Control · Enhancement
AC-19(5) · Full Device or Container-based Encryption
View parent controlControl statement and discussion
NIST control statement
Employ [Selection (one): full-device encryption; container-based encryption] to protect the confidentiality and integrity of information on [Assignment: mobile devices].
Discussion
Container-based encryption provides a more fine-grained approach to data and information encryption on mobile devices, including encrypting selected data structures such as files, records, or fields.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · AC-19 (5) — Direct NIST identifier reference. GovRAMP source matrix
Access Control · Base control
AC-20 · Use of External Systems
Control statement and discussion
NIST control statement
a. [Selection (one-or-more): establish [Assignment: terms and conditions] ; identify [Assignment: controls asserted] ] , consistent with the trust relationships established with other organizations owning, operating, and/or maintaining external systems, allowing authorized individuals to:
1. Access the system from external systems; and
2. Process, store, or transmit organization-controlled information using external systems; or
b. Prohibit the use of [Assignment: prohibited types of external systems].
Discussion
External systems are systems that are used by but not part of organizational systems, and for which the organization has no direct control over the implementation of required controls or the assessment of control effectiveness. External systems include personally owned systems, components, or devices; privately owned computing and communications devices in commercial or public facilities; systems owned or controlled by nonfederal organizations; systems managed by contractors; and federal information systems that are not owned by, operated by, or under the direct supervision or authority of the organization. External systems also include systems owned or operated by other components within the same organization and systems within the organization with different authorization boundaries. Organizations have the option to prohibit the use of any type of external system or prohibit the use of specified types of external systems, (e.g., prohibit the use of any external system that is not organizationally owned or prohibit the use of personally-owned systems).
For some external systems (i.e., systems operated by other organizations), the trust relationships that have been established between those organizations and the originating organization may be such that no explicit terms and conditions are required. Systems within these organizations may not be considered external. These situations occur when, for example, there are pre-existing information exchange agreements (either implicit or explicit) established between organizations or components or when such agreements are specified by applicable laws, executive orders, directives, regulations, policies, or standards. Authorized individuals include organizational personnel, contractors, or other individuals with authorized access to organizational systems and over which organizations have the authority to impose specific rules of behavior regarding system access. Restrictions that organizations impose on authorized individuals need not be uniform, as the restrictions may vary depending on trust relationships between organizations. Therefore, organizations may choose to impose different security restrictions on contractors than on state, local, or tribal governments.
External systems used to access public interfaces to organizational systems are outside the scope of [AC-20](#ac-20) . Organizations establish specific terms and conditions for the use of external systems in accordance with organizational security policies and procedures. At a minimum, terms and conditions address the specific types of applications that can be accessed on organizational systems from external systems and the highest security category of information that can be processed, stored, or transmitted on external systems. If the terms and conditions with the owners of the external systems cannot be established, organizations may impose restrictions on organizational personnel using those external systems.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · AC-20 — Direct NIST identifier reference. GovRAMP source matrix
Access Control · Enhancement
AC-20(1) · Limits on Authorized Use
View parent controlControl statement and discussion
NIST control statement
Permit authorized individuals to use an external system to access the system or to process, store, or transmit organization-controlled information only after:
(a) Verification of the implementation of controls on the external system as specified in the organization’s security and privacy policies and security and privacy plans; or
(b) Retention of approved system connection or processing agreements with the organizational entity hosting the external system.
Discussion
Limiting authorized use recognizes circumstances where individuals using external systems may need to access organizational systems. Organizations need assurance that the external systems contain the necessary controls so as not to compromise, damage, or otherwise harm organizational systems. Verification that the required controls have been implemented can be achieved by external, independent assessments, attestations, or other means, depending on the confidence level required by organizations.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · AC-20 (1) — Direct NIST identifier reference. GovRAMP source matrix
Access Control · Enhancement
AC-20(2) · Portable Storage Devices — Restricted Use
View parent controlControl statement and discussion
NIST control statement
Restrict the use of organization-controlled portable storage devices by authorized individuals on external systems using [Assignment: restrictions].
Discussion
Limits on the use of organization-controlled portable storage devices in external systems include restrictions on how the devices may be used and under what conditions the devices may be used.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · AC-20 (2) — Direct NIST identifier reference. GovRAMP source matrix
Access Control · Enhancement
AC-20(3) · Non-organizationally Owned Systems — Restricted Use
View parent controlControl statement and discussion
NIST control statement
Restrict the use of non-organizationally owned systems or system components to process, store, or transmit organizational information using [Assignment: restrictions].
Discussion
Non-organizationally owned systems or system components include systems or system components owned by other organizations as well as personally owned devices. There are potential risks to using non-organizationally owned systems or components. In some cases, the risk is sufficiently high as to prohibit such use (see [AC-20 b.](#ac-20_smt.b) ). In other cases, the use of such systems or system components may be allowed but restricted in some way. Restrictions include requiring the implementation of approved controls prior to authorizing the connection of non-organizationally owned systems and components; limiting access to types of information, services, or applications; using virtualization techniques to limit processing and storage activities to servers or system components provisioned by the organization; and agreeing to the terms and conditions for usage. Organizations consult with the Office of the General Counsel regarding legal issues associated with using personally owned devices, including requirements for conducting forensic analyses during investigations after an incident.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Access Control · Enhancement
AC-20(4) · Network Accessible Storage Devices — Prohibited Use
View parent controlControl statement and discussion
NIST control statement
Prohibit the use of [Assignment: network-accessible storage devices] in external systems.
Discussion
Network-accessible storage devices in external systems include online storage devices in public, hybrid, or community cloud-based systems.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Access Control · Enhancement
AC-20(5) · Portable Storage Devices — Prohibited Use
View parent controlControl statement and discussion
NIST control statement
Prohibit the use of organization-controlled portable storage devices by authorized individuals on external systems.
Discussion
Limits on the use of organization-controlled portable storage devices in external systems include a complete prohibition of the use of such devices. Prohibiting such use is enforced using technical methods and/or nontechnical (i.e., process-based) methods.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Access Control · Base control
AC-21 · Information Sharing
Control statement and discussion
NIST control statement
a. Enable authorized users to determine whether access authorizations assigned to a sharing partner match the information’s access and use restrictions for [Assignment: information-sharing circumstances] ; and
b. Employ [Assignment: automated mechanisms] to assist users in making information sharing and collaboration decisions.
Discussion
Information sharing applies to information that may be restricted in some manner based on some formal or administrative determination. Examples of such information include, contract-sensitive information, classified information related to special access programs or compartments, privileged information, proprietary information, and personally identifiable information. Security and privacy risk assessments as well as applicable laws, regulations, and policies can provide useful inputs to these determinations. Depending on the circumstances, sharing partners may be defined at the individual, group, or organizational level. Information may be defined by content, type, security category, or special access program or compartment. Access restrictions may include non-disclosure agreements (NDA). Information flow techniques and security attributes may be used to provide automated assistance to users making sharing and collaboration decisions.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · AC-21 — Direct NIST identifier reference. GovRAMP source matrix
Access Control · Enhancement
AC-21(1) · Automated Decision Support
View parent controlControl statement and discussion
NIST control statement
Employ [Assignment: automated mechanisms] to enforce information-sharing decisions by authorized users based on access authorizations of sharing partners and access restrictions on information to be shared.
Discussion
Automated mechanisms are used to enforce information sharing decisions.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Access Control · Enhancement
AC-21(2) · Information Search and Retrieval
View parent controlControl statement and discussion
NIST control statement
Implement information search and retrieval services that enforce [Assignment: information-sharing restrictions].
Discussion
Information search and retrieval services identify information system resources relevant to an information need.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.