DKDavid Koran& Associates
Home The CMMC Guide Part III · Access Control AC.L2-3.1.15
The CMMC Guide · Access Control Family

AC.L2-3.1.15  Authorize Remote Privileged Commands

Authorize remote execution of privileged commands and remote access to security-relevant information.

Family
Access ControlAC, 22 requirements
Point Value
1Lower weight, but not POA&M exempt
POA&M Eligible
YesOne-point requirement, may be deferred
Objectives
FourPer NIST SP 800-171A

1Overview

AC.L2-3.1.15 closes the remote-access cluster by joining it to the privilege controls from earlier in the family. It requires that the most sensitive remote actions, executing privileged commands and reaching security-relevant information from a remote session, be specifically authorized rather than available to anyone who can connect remotely.

The control recognizes that not all remote access is equal. Reading email from home is one thing; reconfiguring a firewall, creating accounts, or viewing the audit configuration from a remote session is another, because these are the actions that can reshape the environment or reveal how it is defended. The requirement is that remote execution of privileged commands and remote access to security-relevant information be permitted only where the organization has deliberately authorized it, so that the ability to connect remotely does not automatically carry the ability to administer remotely. It draws together the least-privilege thinking of 3.1.5 and 3.1.7 with the remote-access controls of this cluster.

The requirement · NIST SP 800-171 Rev 2, 3.1.15

Authorize remote execution of privileged commands and remote access to security-relevant information.

Two remote capabilities are named. "Remote execution of privileged commands" is the performance of administrative actions from a remote session, the same privileged functions governed locally by earlier controls, now reached from outside. "Remote access to security-relevant information" is the ability to view or retrieve the information that describes the security of the environment, such as configurations, logs, and security settings, from a remote session. Both are to be specifically authorized, meaning the organization has decided who may do them remotely and has constrained them accordingly, rather than allowing them as an incidental consequence of remote access.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.1.15 into four objectives: identify the privileged commands and the security-relevant information for remote purposes, then authorize the remote execution of those commands and the remote access to that information.

[a]

Privileged commands authorized for remote execution are identified. The organization has determined which privileged commands, and which security-relevant information, may be executed or reached remotely.

MeetsA defined statement of which administrative actions and security information are permitted from remote sessions, and by whom.
FailsNo distinction is drawn, so any remote session with administrative rights can perform any privileged action.
[b]

Security-relevant information authorized to be accessed remotely is identified. The organization has determined which security-relevant information, such as security configurations and audit logs, may be reached remotely and by which roles.

MeetsA defined statement of which security information is reachable from remote sessions, and by whom.
FailsNo distinction is drawn, so it is undefined which security information may be reached remotely.
[c]

The execution of the identified privileged commands via remote access is authorized. The system enforces the authorization, so remote privileged actions occur only where allowed.

MeetsRemote administrative capability is restricted to authorized administrators through their controlled access, and general remote users cannot perform privileged actions.
FailsThe authorization exists on paper while every remote administrator can execute any privileged command regardless.
[d]

Access to the identified security-relevant information via remote access is authorized. Remote access to security configurations and logs is limited to the specific administrators authorized for it.

MeetsRemote access to security settings and audit data is confined to the administrators specifically authorized for it.
FailsAny remote user with broad access can view security settings and audit data without specific authorization.

The four objectives move from identifying the privileged commands and security information to authorizing their remote execution and access. The control depends heavily on the privilege structure already built, because authorizing remote privileged actions is only meaningful where privilege is differentiated in the first place; in a flat model where everyone is an administrator, there is nothing specific to authorize and objectives [c] and [d] cannot hold.

3Failure Patterns

The failures follow from privilege that is not differentiated and from remote administration that was never scoped separately from remote access in general.

Remote access equals remote administration

Where anyone who connects remotely and holds administrative rights can perform any privileged action, the control has nothing to enforce, because remote privileged execution was never treated as a distinct capability requiring authorization. This is the core failure, and it usually reflects the same flat-privilege model that undermines the earlier least-privilege controls.

Security information reachable by any remote session

Configurations, logs, and security settings that any broadly privileged remote user can view fail objective [d], because remote access to security-relevant information was not specifically authorized or constrained. The information that describes how the environment is defended is exactly what should be reachable remotely only by those authorized for it.

The authorization that is not enforced

A policy may state which administrators are authorized for remote privileged actions while nothing in the system actually restricts remote administration to them, so objective [c] fails even though [a] and [b] are documented. The authorization has to be enforced by the access configuration, not merely written down.

Standing remote administrative access

Broad, permanent remote administrative capability, always available rather than granted for authorized purposes, widens the exposure the control seeks to narrow. Even where the administrators are the right ones, remote privileged access that is always on is harder to justify than access aligned to authorized need, and it is the pattern a maturing program tightens.

The common root
This control fails where privilege is undifferentiated, because there is nothing specific to authorize. It presumes the earlier least-privilege work: only once privileged actions are distinct from ordinary ones can the organization authorize which of them may be performed remotely.

4Ownership

This control is owned by IT and builds directly on the privilege structure, so its ownership overlaps with the least-privilege controls, extended to the remote case.

RoleResponsibility for this control
IT and system administratorIdentifies the privileged commands and security information relevant to remote use, restricts remote privileged capability to authorized administrators, and enforces it through the access configuration. Owns the technical evidence.
Security or compliance leadDefines and authorizes which remote privileged actions and security-information access are permitted and by whom, and confirms enforcement matches the authorization.
Program leadIncludes remote privileged access in periodic review of privileged accounts, since standing remote administrative capability is what the review should surface, and retains the records.
See also: This control extends the least-privilege model of AC.L2-3.1.5 and the privileged-function control of AC.L2-3.1.7 to remote sessions, and it completes the remote-access cluster that begins at AC.L2-3.1.12.

5Tooling

The control is built on the existing privilege structure and the remote access path, constrained so that privileged remote actions are available only to authorized administrators.

ObjectivesToolingWhat it provides
[a]–[d]Access policy defining remote privileged actions and security-information accessThe documented identification and authorization of which privileged commands and security information may be reached remotely, and by whom.
[c] enforcementRole-based administrative access, Conditional Access, privileged access managementRestricting remote administrative capability to authorized administrators, so a general remote session cannot execute privileged commands or reach security information.
[c] strengtheningJust-in-time elevation, privileged access workstations, jump hosts for administrationGranting remote privileged access for authorized purposes rather than as standing capability, and channeling remote administration through controlled paths.
VerificationPrivileged-action logs from remote sessionsRecords showing remote privileged actions performed by authorized administrators, tying to the auditing of privileged functions.

The caveat is that this control cannot stand on a flat privilege model. If every administrator can already do everything and everyone is an administrator, there is no authorization to enforce, so the work here presumes the least-privilege structure of the earlier controls and extends it to the remote case. The assessor tests objectives [c] and [d] by checking whether a remote session can perform privileged actions or reach security information without specific authorization, which depends on privilege being differentiated to begin with.

6Evidence

The satisfied version of 3.1.15 shows the identified remote privileged actions, their authorization, and the enforcement that confines them.

EvidenceWhat it demonstrates
Remote privileged action authorizationObjectives [a]–[d]. The documented identification and authorization of remote privileged commands and security-information access.
Remote administrative access configurationObjective [c]. The restriction of remote privileged capability to authorized administrators.
Privileged access management or elevation recordsObjective [c]. Evidence that remote privileged access is granted as authorized rather than standing broadly.
Remote privileged-action logsObjective [c]. Records of remote privileged actions performed by authorized administrators.

The evidence should show that remote privileged capability is confined to authorized administrators and that a general remote session cannot perform privileged actions or reach security information, which rests on the differentiated privilege structure from the earlier controls. Logs of remote privileged actions, tied to the authorized administrators who performed them, connect this control to the auditing of privileged functions and demonstrate the enforcement in practice.

Remote administration is a capability to scope, not a default

The ability to connect remotely should not silently carry the ability to administer remotely, and separating the two rests on a privilege structure that distinguishes the powerful actions from the ordinary ones. Scoping remote privileged access to the administrators authorized for it, and building on the least-privilege work it depends on, is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.1.15. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.1.15[a] through 3.1.15[d]. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in Access Control
AC.L2-3.1.14 · Route Remote Access Through Managed Points
Next in Access Control →
AC.L2-3.1.16 · Authorize Wireless Access
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry AC.L2-3.1.15 · Edition 2026.1 · Last reviewed July 12, 2026