GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

IAM-011 Remote Access Controls

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Remote access to internal systems and infrastructure is controlled through approved, documented access paths (e.g. VPN, zero-trust network access). Unapproved remote access methods are blocked. Remote access sessions require MFA and are logged. Access paths are reviewed and re-authorised periodically.

Rationale

Remote access bypasses perimeter controls and is a common attack vector. Formalised remote access paths with authentication and logging ensure that remote sessions are accountable and auditable.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (9)

8.5Secure authenticationinformative
NIS2-CIR-6.7Network Securityinformative
AC-17Remote Accessfull
AC-17(1)Remote Access | Monitoring and Controlpartial
AC-17(3)Remote Access | Managed Access Control Pointsfull
AC-17(4)Remote Access | Privileged Commands and Accesspartial
MA-4Nonlocal Maintenancepartial
SC-7(7)Boundary Protection | Split Tunneling for Remote Devicespartial
CC6.6Security Measures Against Threats Outside System Boundariespartial

Evidence (2)

configurationtechnicalautomated

Remote access configuration showing that only approved access paths (VPN, ZTNA) are permitted and that MFA is enforced for all remote sessions.

Example: VPN gateway configuration export (e.g. Cisco AnyConnect, OpenVPN) or ZTNA policy export (e.g. Cloudflare Access, Zscaler ZPA) showing: approved access paths, MFA enforcement setting, session timeout, and network policy blocking unapproved remote methods.

Test: Request the VPN or ZTNA configuration. Verify: (1) remote access requires MFA at the gateway level, (2) session timeout is set per policy, (3) firewall or network policy explicitly blocks inbound SSH, RDP, or direct API access from the internet to internal systems except through the approved path, (4) the policy was reviewed and re-authorised within the last 12 months.

logtechnicalautomated

Remote access session logs showing all remote connections over the past 30 days with user identity, source IP, timestamp, and session duration.

Example: VPN gateway log export or ZTNA access log export covering the last 30 days, showing each session's authenticating user, source IP, destination system, start time, and end time.

Test: Export remote access session logs for the past 30 days. Verify: (1) every session has a named authenticated user, with no anonymous or service-account sessions without documented justification, (2) all source IPs are within expected geographic/network ranges or have a corresponding approved exception, (3) log retention meets the policy-defined period.

Questions (2)

boolean

Is remote access to internal systems and infrastructure limited to approved, documented access paths (e.g. VPN or zero-trust network access)?

Direct SSH, RDP, or API access from the internet to internal resources without a sanctioned gateway should be blocked. All remote access paths must be reviewed and reauthorised periodically.

select

What remote access technology is in use for accessing internal systems?

Identity-aware access proxy that authorises each connection against the user, the device and the resourceEncrypted tunnel requiring multi-factor authenticationBastion or jump host requiring multi-factor authentication at the gatewayEncrypted tunnel or bastion with single-factor authenticationInternal systems reachable directly from the public internetNo defined remote access path

Options run from the strongest path to the weakest. An identity-aware proxy decides each connection on its own terms, so one stolen credential does not open the internal network the way a tunnel credential does; Cloudflare Access, Zscaler Private Access and BeyondCorp are examples of the category. A tunnel with multi-factor authentication is the floor this control expects. An internal system reachable directly from the public internet is a critical finding. Record the capability in use rather than the product name.