CMMC Level 2

Control 3.1.14

Route Remote Access via Managed Access Control Points

CMMC-RP Certified Team 24+ Years Experience CMMC-AB RPO #1449

Official Requirement

Route remote access via managed access control points.

What This Means in Plain English

All remote connections must go through a limited number of controlled entry points (like a VPN gateway or secure web portal). Users should not be able to bypass these gateways and connect directly to internal systems.

How Petronella Implements This Control

Petronella Technology Group implements this control through:

  • All remote access routed through FortiGate VPN concentrator as the sole managed entry point
  • FortiGate firewall rules blocking direct external access to internal resources
  • Cisco Meraki SD-WAN ensuring branch office traffic routes through central security controls
  • Microsoft Entra Application Proxy providing secure access to internal web applications without direct exposure
  • Network architecture documentation showing all managed access control points

Assessment Guidance

Assessors will review network diagrams confirming all remote access flows through managed access points, test that direct connections to internal systems from external networks are blocked, and verify that all access control points are monitored.

Common Implementation Gaps

  • Direct RDP or SSH ports exposed to the internet
  • Shadow IT cloud services bypassing the corporate VPN
  • IoT devices with direct internet connectivity
  • No network diagram showing managed access control points
  • Multiple unmonitored entry points into the network

Cross-Framework Mapping

FrameworkMapped Controls
NIST SP 800-53AC-17(3)
PCI DSSReq 1.3 - Restrict inbound and outbound traffic
CP
By Craig Petronella
Founder, Petronella Technology Group | CMMC-RP (RPO #1449) | DFE #604180 | MIT-Certified in AI and Blockchain
Craig has helped North Carolina defense contractors prepare for CMMC assessments since 2002 and authored the CMMC 2.0 Certification Guide. Read the LinkedIn profile or verify the RPO listing at the CyberAB Marketplace.

Need Help Implementing 3.1.14?

Our CMMC-RP certified team can assess your current compliance posture and build a remediation plan.

Schedule a Compliance Assessment Calculate your SPRS score