NIST 800-171 Controls · Access Control
AC.2.012 — Monitor and Control Remote Access Sessions
Monitor and control remote access sessions.
What AC.2.012 means in plain English
If your employees (or IT support) access your company's systems from outside the office — from home, on the road, or via a support vendor — you need to know when those remote sessions happen, who initiated them, and be able to shut them down if something looks wrong. You can't just have an open door into your systems without watching who's coming through.
The assessment question
“Do you have a way to see who is currently connected remotely to your systems, do you keep logs of remote access sessions (who connected, from where, when), and can you terminate a suspicious remote session if needed?”
How to implement AC.2.012
- Use a VPN for all remote access rather than exposing Remote Desktop directly to the internet. OpenVPN Access Server (free for up to 2 connections) or a hardware VPN router (Cisco RV series, ~$100-$300) centralizes remote connections through one monitored gateway.
- Enable Windows Event Logging for remote connections: in Event Viewer, Security logs capture logon events (Event ID 4624 for successful logon, 4625 for failed). Enable these under Local Security Policy > Audit Policy.
- In Microsoft 365 GCC, use Microsoft Entra Sign-in Logs to monitor all cloud-based remote access: Azure Portal > Microsoft Entra ID > Monitoring > Sign-in logs. Review this monthly.
- For IT support vendors, use a PAM (Privileged Access Management) tool like BeyondTrust Remote Support Free or AnyDesk Business to ensure vendor sessions are recorded and you must approve them before they connect.
- Create a remote access log review procedure: designate someone to review remote access logs weekly, and document that review with a dated sign-off.
Evidence your assessor will ask for
- VPN or remote access solution configuration showing logging is enabled
- Sample remote access log entries (with PII redacted if needed for review)
- Written Remote Access Policy describing monitoring requirements
- Process or procedure for periodic review of remote access logs
- Evidence of log review (dated sign-off or ticketing system entry)
Does AI prompt monitoring help with this control? Honestly, no.
AC.2.012 is met through the remediation steps above, not through AI traffic controls — an AI prompt firewall neither satisfies nor substitutes for it. We map AI monitoring only to the controls it genuinely evidences (flow control, boundary protection, audit, and incident support); for the full picture of where it does help, see the mapping guide linked below.
Full mapping: which 800-171 controls AI prompt monitoring evidences →
More Access Control controls
Score yourself against all 110 controls
The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.