Security Requirements for 03.01.20 Use of External Systems

External systems are systems that are used by but are not part of the organization. These systems include personally owned systems, system components, or devices; privately owned computing and communication devices in commercial or public facilities; systems owned or controlled by nonfederal organizations; and systems managed by contractors. Organizations have the option to prohibit the use of any type of external system or specified types of external systems (e.g., prohibit the use of external systems that are not organizationally owned). Terms and conditions are consistent with the trust relationships established with the entities that own, operate, or maintain external systems and include descriptions of shared responsibilities. Authorized individuals include organizational personnel, contractors, or other individuals with authorized access to the organizational system and over whom organizations have the authority to impose specific rules of behavior regarding system access. Restrictions that organizations impose on authorized individuals may vary depending on the trust relationships between organizations. Organizations need assurance that external systems satisfy the necessary security requirements so as not to compromise, damage, or harm the system. This requirement is related to 03.16.03.

View CPRT 03.01.20
  1. 03.01.20.a

    Prohibit the use of external systems unless the systems are specifically authorized.

  1. 03.01.20.b

    Establish the following security requirements to be satisfied on external systems prior to allowing use of or access to those systems by authorized individuals: [Assignment: organization-defined security requirements].

  1. 03.01.20.c

    Permit authorized individuals to use external systems to access the organizational system or to process, store, or transmit CUI only after:

  2. 03.01.20.c.01

    Verifying that the security requirements on the external systems as specified in the organization’s system security plans have been satisfied and

  3. 03.01.20.c.02

    Retaining approved system connection or processing agreements with the organizational entities hosting the external systems.

  1. 03.01.20.d

    Restrict the use of organization-controlled portable storage devices by authorized individuals on external systems.