Skip to main content

πŸ’Ό AC-20 Use of External Systems

  • Contextual name: πŸ’Ό AC-20 Use of External Systems
  • ID: /frameworks/nist-sp-800-53-r5/ac/20
  • Located in: πŸ’Ό AC Access Control

Description​

a. [Selection (one or more): Establish [Assignment: organization-defined terms and conditions]; Identify [Assignment: organization-defined controls asserted to be implemented on external systems]], consistent with the trust relationships established with other organizations owning, operating, and/or maintaining external systems, allowing authorized individuals to:

  1. Access the system from external systems; and
  2. Process, store, or transmit organization-controlled information using external systems; or b. Prohibit the use of [Assignment: organizationally-defined types of external systems].

Similar​

  • Internal
    • ID: dec-c-70810614

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό FedRAMP High Security Controls β†’ πŸ’Ό AC-20 Use of External Systems (L)(M)(H)2
πŸ’Ό FedRAMP Low Security Controls β†’ πŸ’Ό AC-20 Use of External Systems (L)(M)(H)
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό ID.AM-02: Inventories of software, services, and systems managed by the organization are maintained7
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό ID.AM-04: Inventories of services provided by suppliers are maintained

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό AC-20(1) Use of External Systems _ Limits on Authorized Use
πŸ’Ό AC-20(2) Use of External Systems _ Portable Storage Devices β€” Restricted Use
πŸ’Ό AC-20(3) Use of External Systems _ Non-organizationally Owned Systems β€” Restricted Use
πŸ’Ό AC-20(4) Use of External Systems _ Network Accessible Storage Devices β€” Prohibited Use
πŸ’Ό AC-20(5) Use of External Systems _ Portable Storage Devices β€” Prohibited Use