Skip to content

AC-20: Use of External Systems

An OSCAL Control

Statement

    • a.

      , consistent with the trust relationships established with other organizations owning, operating, and/or maintaining external systems, allowing authorized individuals to:

      • 1.

        Access the system from external systems; and

      • 2.

        Process, store, or transmit organization-controlled information using external systems; or

    • b.

      Prohibit the use of .

      • Guidance:

        The interrelated controls of AC-20, CA-3, and SA-9 should be differentiated as follows:

        AC-20 describes system access to and from external systems.

        CA-3 describes documentation of an agreement between the respective system owners when data is exchanged between the CSO and an external system.

        SA-9 describes the responsibilities of external system owners. These responsibilities would typically be captured in the agreement required by CA-3.