This objective ensures your organization has formally documented all encrypted remote access sessions used to connect to systems storing, processing, or transmitting Controlled Unclassified Information (CUI). The documentation must describe how remote access is secured and where encryption is enforced.