AC-17 Remote Access: Same Answer, Different Implementation

Two agencies. Same checklist answer: remote access to CJI systems is controlled and monitored in accordance with AC-17. Both rated themselves compliant.

The auditor asked which remote access methods are authorized.

Agency A named the VPN. It is the only authorized path. The policy said so, the technical configuration enforced it, and the LASO could show the log of who connected, when, and from where for the past 90 days.

Agency B named the VPN. Also mentioned that officers sometimes connect from personal laptops when on call. Also mentioned that the IT vendor has direct RDP access for maintenance windows. The policy said "authorized remote access methods," but the list of authorized methods was not written down anywhere. The monitoring log showed VPN sessions. It did not show the RDP sessions because those went through a different path.

The auditor found two unmonitored remote access vectors and a policy that named a requirement without defining its scope.

What the control actually requires

AC-17 requires the organization to establish usage restrictions, configuration and implementation guidance, and documentation for each remote access method. It requires authorization before allowing remote connections. It requires monitoring and control of remote access sessions. It requires encryption on all remote sessions handling CJI.

"Each remote access method" is the phrase that matters. A VPN policy that does not address vendor access, personal device access, or administrative access to supporting infrastructure does not satisfy AC-17 for those vectors regardless of whether those vectors are in use.

AC-17 is Existing and applies to whatever methods are in use, not whatever methods the policy acknowledges.

What the auditor is looking for

A complete authorized-methods list with the technical controls for each. Monitoring logs that capture all authorized sessions, not just the primary path. An exception or authorization process for any access that falls outside the normal method. Evidence that encryption is in place on sessions carrying CJI.

If the vendor has RDP access, that access needs to be authorized, logged, and monitored. If officers connect from personal devices, that method needs to be authorized with defined controls or prohibited explicitly. A policy that does not account for the actual access landscape does not document what the policy claims to document.

The common failure mode

The primary remote access method is well-controlled. The secondary methods — vendor access, emergency access, administrative paths — developed over time without being formalized, monitored, or addressed in the policy. An auditor who asks broadly gets the VPN answer. An auditor who asks specifically gets a more complicated picture.

Written by Dr. Alexis W. Perdereaux-Weekes

DBA · CISA · CISM · CRISC · CDPSE

Founder, CJIS360 LLC


Sources: CJIS Security Policy v6.1, 06/25/2026 — AC-17 Remote Access; AC-17(1) Monitoring and Control; AC-17(2) Protection of Confidentiality and Integrity Using Encryption; §1.4 Terminology Used in This Document.

Questions about how this applies to your agency: agency@cjis360.com

Back to the Knowledge Center