{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Network & Communications Security","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-NET-02","description":"Establish usage restrictions, configuration and connection requirements, and explicit authorization for each type of remote access, wireless access, and organization-controlled mobile device before connection is permitted. Protect these connections with mutual authentication, encryption, and wireless link-level protections commensurate with the signal exposure and threat environment, and monitor for unauthorized access points and connections.","details":{"control_category":"technical","control_type":"preventive","domain":"Network & Communications Security","guidance":[],"members":[{"control_id":"AC-17","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"AC-18","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"AC-19","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SC-40","coverage":"full","framework":"nist-800-53","relationship":"superset_of"}],"statement":"Establish usage restrictions, configuration and connection requirements, and explicit authorization for each type of remote access, wireless access, and organization-controlled mobile device before connection is permitted. Protect these connections with mutual authentication, encryption, and wireless link-level protections commensurate with the signal exposure and threat environment, and monitor for unauthorized access points and connections.","title":"Authorize and secure remote, wireless, and mobile access","unified_id":"UC-NET-02"},"id":"uc:UC-NET-02","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-NET-02","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"UC-NET-02 — Authorize and secure remote, wireless, and mobile access","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0083b823d1479a811e274089f6658e2a1a882805ebf8b83b5a50a508f6260427","properties":{"control_id":"AC-19","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-02-6e84b235.json","sourceId":"uc:UC-NET-02","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ac-19-ec21db96.json","targetId":"ctrl:nist-800-53:AC-19","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:49d93e5d29de0c10f132b1916dd14d56d4b1e8db459ed4630beaf75483a914c6","properties":{},"sourceDetailPath":"/data/v1/records/wf-c10-29ff1ddb.json","sourceId":"wf:C10","targetDetailPath":"/data/v1/records/uc-uc-net-02-6e84b235.json","targetId":"uc:UC-NET-02","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4e08d3733dbf0df01fcd67f770bddac361278d78363b96313f19dd977fe43c0d","properties":{"control_id":"SC-40","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-02-6e84b235.json","sourceId":"uc:UC-NET-02","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-40-3d233d47.json","targetId":"ctrl:nist-800-53:SC-40","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5200eef6e0cd5fadc996700f1e305a155cac5ecdde4190bec944281139d8896c","properties":{"rationale":"Requiring mutual authentication before a remote connection is permitted reduces account compromise on those channels; MFA/password policy owned elsewhere.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-net-02-6e84b235.json","sourceId":"uc:UC-NET-02","targetDetailPath":"/data/v1/records/risk-access-weak-authentication-4e35bdb2.json","targetId":"risk:access-weak-authentication","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:649e529c9a9818779f804d162b20c955e77fa360adabe1b6097b6c3ca4e46a95","properties":{"rationale":"Mandating encryption for remote/wireless/mobile transmission reduces unencrypted-in-transit exposure; storage and key management addressed elsewhere.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-net-02-6e84b235.json","sourceId":"uc:UC-NET-02","targetDetailPath":"/data/v1/records/risk-crypto-weak-or-absent-encryption-2fe7d24e.json","targetId":"risk:crypto-weak-or-absent-encryption","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6c042b8818f6bdd7d6cd06ff479c4d339db9da7a2c8091c2c390fa14ef9c7c66","properties":{},"sourceDetailPath":"/data/v1/records/wf-c49-5eff4769.json","sourceId":"wf:C49","targetDetailPath":"/data/v1/records/uc-uc-net-02-6e84b235.json","targetId":"uc:UC-NET-02","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6c407b10ad5d46151c7ff6fecca5f3a9ca0646ad8c5f14b8b5cb13ef0c20f1ba","properties":{"control_id":"AC-18","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-02-6e84b235.json","sourceId":"uc:UC-NET-02","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ac-18-e2c1b10c.json","targetId":"ctrl:nist-800-53:AC-18","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6f4ebe282667f400a5fd156357e960f34537bcd81eccd953429a6cc082ddfc02","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-net-02-6e84b235.json","targetId":"uc:UC-NET-02","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:882b2dcd33aa7402e887b3ecca36b20c92a1e58bd219b380698c02684af44a73","properties":{"rationale":"Explicit authorization, usage/connection restrictions, and encryption for each remote/wireless/mobile connection is the operative control for insecure remote and mobile access.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-net-02-6e84b235.json","sourceId":"uc:UC-NET-02","targetDetailPath":"/data/v1/records/risk-net-remote-work-mobile-exposure-d7aab6d9.json","targetId":"risk:net-remote-work-mobile-exposure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9995e98d5723f34ecb02cc539ca290049e759a06e7a6d330770506cc96231c67","properties":{"rationale":"Encryption, wireless link-level protection, and mutual authentication defeat eavesdropping, wireless interception, and man-in-the-middle on these links.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-net-02-6e84b235.json","sourceId":"uc:UC-NET-02","targetDetailPath":"/data/v1/records/risk-net-interception-mitm-2a226fa0.json","targetId":"risk:net-interception-mitm","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dacb14bcd5fcf3e19fd06ff4c931b9abb801f1b0971f99063c8e4076aedab5b8","properties":{"control_id":"AC-17","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-02-6e84b235.json","sourceId":"uc:UC-NET-02","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ac-17-4b0ce4dd.json","targetId":"ctrl:nist-800-53:AC-17","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:eb180c76ac7e710e13f9e48814b17340ae292935a08931f64bee369172698524","properties":{"rationale":"Mandatory mutual authentication and encryption on remote/wireless links prevent credential interception and spoofing on those channels.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-net-02-6e84b235.json","sourceId":"uc:UC-NET-02","targetDetailPath":"/data/v1/records/risk-crypto-cleartext-credential-transfer-b88065a1.json","targetId":"risk:crypto-cleartext-credential-transfer","type":"mitigates"}],"schemaVersion":1}
