|
controlAC-20

Use of External Systems (AC-20)

[organization-defined] , consistent with the trust relationships established with other organizations owning, operating, and/or maintaining external systems, allowing authorized individuals to: Prohibit the use of [organization-defined].

Security Baselines

LOWMODERATEHIGH
access-controlauthorizationleast-privilege

Why These Connect

Maps To5

These are equivalent or closely aligned requirements in other frameworks.

Baselined In3

This control is included in the linked security baseline (LOW, MODERATE, or HIGH).

Supports19

These related controls work together — a change to one may affect the others.

Enhances5

These enhancements add specific capabilities or refinements to the base control.

Cross-Framework Mappings(5)

ID.AM-02ID.AM-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.AM-04ID.AM-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20223 mappingsFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
ID.AM-02ID.AM-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.AM-04ID.AM-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5

Organization-Defined Parameters(4)

SelectionSelection (one-or-more): establish {{ insert: param, ac-20_odp.02 }} / identify {{ insert: param, ac-20_odp.03 }}
Assignmentorganization-defined terms and conditions
Assignmentorganization-defined controls asserted
Assignmentorganization-defined prohibited types of external systems

Control Enhancements(5)