Control Mapping Readerplace a control, see the map

NIST800-AC-20 AC-20 Use of External Systems

NIST800-AC-20 in NIST SP 800-53 Rev 5 (NIST SP 800-53 Rev 5, Release 5.2.0). All NIST SP 800-53 Rev 5 controls held. Open NIST SP 800-53 Rev 5 on the standards site.

The control as we hold it

AC-20 Use of External Systems. a. [Selection (one or more): establish [Assignment: organization-defined terms and conditions]; identify [Assignment: organization-defined controls asserted to be implemented on external systems]], consistent with the trust relationships established with other organizations owning, operating, and/or maintaining external systems, allowing authorized individuals to: 1. Access the system from external systems; and 2. Process, store, or transmit organization-controlled information using external systems; or b. Prohibit the use of [Assignment: organizationally-defined types of external systems].

Reviewed and closest counterparts in the other frameworks

Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.

SOC 2

HIPAA Security Rule

What an auditor commonly asks for

General guidance for this control area (domain: AC - Access Control), in our words, not a statement of the standard and not binding on an assessor.

Buy the reviewed crosswalk pair Place your own control