Canada's addition, 03.14.09: dedicated administration workstation. This is the one requirement in ITSP.10.171 that isn't in NIST SP 800-171, and it comes from the Canadian control catalogue (source control SI-400, the ITSG-33 lineage) rather than from NIST. It asks for 3 things. Administrative and superuser actions get done from a physical workstation dedicated to that work and isolated from all other functions and networks, especially the internet. Remote connection from that workstation to the network it administers runs over a carrier private network, such as VPLS or MPLS, with VPN encryption on top. And the workstation is a hardened, single-purpose machine or thin client that isn't shared between security realms. The discussion in the standard goes further than most shops expect: the workstation isn't domain-joined, doesn't download patches from the internet, carries no office tools, and isn't used to update documentation in networked applications.
For a 20-person shop that means one admin machine, kept off the internet, patched from media you bring to it, and used for nothing but administering the enclave; admin accounts work from that machine and from nowhere else.
The remote clause is the hard part. An MSP administering your enclave from its own office over an internet VPN doesn't meet the requirement as written, and a carrier private network to every client is not how most MSPs are built. This is a Level 2 requirement, it's new, and the assessment method hasn't been published... so read the text yourself, keep administrative work inside the enclave wherever you can, and get your assessor's reading in writing before you buy circuits.