Skip to main content

💼 AC-20 USE OF EXTERNAL INFORMATION SYSTEMS

  • ID: /frameworks/nist-sp-800-53-r4/ac/20

Description​

The organization establishes terms and conditions, consistent with any trust relationships established with other organizations owning, operating, and/or maintaining external information systems, allowing authorized individuals to: AC-20a. Access the information system from external information systems; and AC-20b. Process, store, or transmit organization-controlled information using external information systems.

Similar​

  • Internal
    • ID: dec-c-fcf6e6c8

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 NIST CSF v1.1 → 💼 ID.AM-4: External information systems are cataloguedno data
💼 NIST CSF v1.1 → 💼 PR.AC-3: Remote access is managed22no data

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 AC-20 (1) LIMITS ON AUTHORIZED USEno data
💼 AC-20 (2) PORTABLE STORAGE DEVICESno data
💼 AC-20 (3) NON-ORGANIZATIONALLY OWNED SYSTEMS _ COMPONENTS _ DEVICESno data
💼 AC-20 (4) NETWORK ACCESSIBLE STORAGE DEVICESno data