Skip to main content

💼 AC-20 USE OF EXTERNAL INFORMATION SYSTEMS

  • Contextual name: 💼 AC-20 USE OF EXTERNAL INFORMATION SYSTEMS
  • ID: /frameworks/nist-sp-800-53-r4/ac/20
  • Located in: 💼 AC ACCESS CONTROL

Description​

The organization establishes terms and conditions, consistent with any trust relationships established with other organizations owning, operating, and/or maintaining external information systems, allowing authorized individuals to: AC-20a. Access the information system from external information systems; and AC-20b. Process, store, or transmit organization-controlled information using external information systems.

Similar​

  • Internal
    • ID: dec-c-fcf6e6c8

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
💼 NIST CSF v1.1 → 💼 ID.AM-4: External information systems are catalogued
💼 NIST CSF v1.1 → 💼 PR.AC-3: Remote access is managed1

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
💼 AC-20 (1) LIMITS ON AUTHORIZED USE
💼 AC-20 (2) PORTABLE STORAGE DEVICES
💼 AC-20 (3) NON-ORGANIZATIONALLY OWNED SYSTEMS _ COMPONENTS _ DEVICES
💼 AC-20 (4) NETWORK ACCESSIBLE STORAGE DEVICES