NIST SP 800-53 Rev 5
AC - Access Control

NIST SP 800-53 Rev 5 NIST800-AC-20: AC-20 Use of External Systems

a. [Selection (one or more): establish [Assignment: organization-defined terms and conditions]; identify [Assignment: organization-defined controls asserted to be implemented on external systems]], consistent with the trust relationships established with other organizations owning, operating, and/or maintaining external systems, allowing authorized individuals to: 1. Access the system from external systems; and 2. Process, store, or transmit organization-controlled information using external systems; or b. Prohibit the use of [Assignment: organizationally-defined types of external systems].

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 188 controls across 95 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 6 controls

  • 1.4.1 1.4.1 NSCs between trusted and untrusted networks
  • 1.5.1 1.5.1 Security controls on dual-connected devices
  • 12.8.2 12.8.2 TPSP contracts acknowledging account data responsibility
  • 12.8.3 12.8.3 Due diligence before engaging TPSPs
  • 12.8.4 12.8.4 Annual monitoring of TPSP compliance status
  • 8.2.7 8.2.7 Third-party remote access accounts controlled

SOC 2 · 5 controls

  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary
  • SOC2-CC9.2 CC9.2 Assessing and managing vendor and business partner risk
  • SOC2-P6.4 P6.4 Privacy commitments from vendors and third parties
  • SOC2-P6.5 P6.5 Vendor commitments to report unauthorised disclosures

FedRAMP High · 4 controls

  • AC-20 Use of External Systems
  • AC-20(1) Limits on Authorized Use
  • AC-20(2) Portable Storage Devices Restricted Use
  • PL-4(1) Rules of Behavior | Social Media and External Site/Application Usage Restrictions (PL-4(1))

FedRAMP Moderate · 4 controls

  • AC-20 Use of External Systems
  • AC-20(1) Limits on Authorized Use
  • AC-20(2) Portable Storage Devices Restricted Use
  • PL-4(1) Rules of Behavior | Social Media and External Site/Application Usage Restrictions (PL-4(1))

HIPAA Security Rule · 4 controls

ISO 27701:2019 · 4 controls

  • 6.10.2 Information transfer
  • 6.12.1 Information security in supplier relationships
  • 6.6.2 User access management
  • 6.9.4 Logging and monitoring

API 1164 · 3 controls

  • API1164-06 Access Control
  • API1164-07 Remote Access
  • API1164-09 Patch and Vulnerability Management

BSI IT-Grundschutz · 3 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions

IEC 62443 · 3 controls

  • IEC62443-07 Personnel risk assessment
  • IEC62443-08 Electronic access perimeter management
  • IEC62443-10 Revocation of access procedures

ISO 27002:2022 · 3 controls

  • 5.20 Addressing information security within supplier agreements
  • 5.22 Monitoring, review and change management of supplier services
  • 5.23 Information security for use of cloud services

ISO 27799:2025 · 3 controls

  • ISO27799-01 ePHI access controls and authorization
  • ISO27799-08 Information access management
  • ISO27799-17 Facility access controls

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-07 Personnel risk assessment
  • ISO27019-08 Electronic access perimeter management
  • ISO27019-10 Revocation of access procedures

ISO/IEC 27043:2015 · 3 controls

  • ISO27043-11 Access control policy and enforcement
  • ISO27043-14 Privileged access management
  • ISO27043-15 Access review and recertification

ISO/SAE 21434 · 3 controls

  • ISO21434-12 User access management and provisioning
  • ISO21434-14 Privileged access management
  • ISO21434-15 Access review and recertification

NIST SP 1800-32 · 3 controls

  • ANSSI-HYG-07 Authorise Network Connection Only for Managed Equipment
  • ANSSI-HYG-25 Secure Dedicated Network Interconnections with Partners
  • AWWA-2.1 User Access Management
  • AWWA-2.4 Physical Access Controls
  • AM-2 Use only approved services
  • ASBv3-PA-8 Determine access process for cloud provider support

CMMC 2.0 · 2 controls

  • DSO-2 Data Security
  • DSO-3 Data Access Management
  • CAT-D3-1 Preventative controls
  • CAT-D4-3 Third-party access controls

ISO/IEC 27010:2015 · 2 controls

  • 27010-9.1 Access Control to Shared Information
  • 27010-9.2 Authentication of Sources

ISO/IEC 27011:2024 · 2 controls

  • 27011-5.3 Segregation of duties
  • 27011-8.1 User Endpoint Devices

NIST SP 800-161 Rev 1 · 2 controls

  • 161R1-AC-20 Use of External Systems
  • 161R1-PM-17 Protecting Controlled Unclassified Information on External Systems

NIST SP 800-66 Rev 2 · 2 controls

SLSA · 2 controls

  • SUPCHAIN-1 Build Integrity - Source, Build, Provenance
  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule

South Korea ISMS-P · 2 controls

  • ISMSP-AC-01 Access Control Policy
  • ISMSP-AC-04 Network Access Control

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • SEC03-BP09 Share resources securely with a third party

Bahrain PDPL · 1 control

C5 (Germany) · 1 control

  • C5-SSO-01 Policies and instructions for controlling and monitoring third parties

CIS Controls v8 · 1 control

  • CIS-4.12 Separate Enterprise Workspaces on Mobile End-User Devices

CMMC 2.0 Level 1 · 1 control

  • CA-ITSG33-SC-01 Security Control Catalogue
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)
  • IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • 62351-8 Role-based access control (RBAC)

ISO 27001:2022 · 1 control

  • 5.23 Information security for use of cloud services
  • ISO28001-PS-01 Facility Security
  • ISO20000-15 Access management for services

ITIL 4 · 1 control

  • ITIL4-15 Access management for services
  • NIST-CSF-GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
  • NISTPF-5 Protect-P Access Control (PR.AC-P)

NIST SP 800-161 · 1 control

NIST SP 800-172 · 1 control

  • 3.1.2e Restrict Access to Organization-Owned, Provisioned, or Issued Information Resources

NIST SP 800-207 · 1 control

  • AC-20 AC-20 Use of External Systems
  • AC-20 AC-20 Use of External Systems
  • AC-20 AC-20 Use of External Systems
  • NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access

NIST SP 800-88 · 1 control

  • NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework

NIST SP 800-92 · 1 control

  • NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control
  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul

OWASP SAMM · 1 control

  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture
  • OMANCS-3 Identity and Access Management, Authentication, Privileged Access

OpenSSF Scorecard · 1 control

  • OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices
  • PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working

PDPA Singapore · 1 control

  • PDPASG-5 Protection, Accuracy, and Security of Personal Data

PDPA Thailand · 1 control

  • PDPATH-5 Security Measures and Data Protection

POPIA · 1 control

  • POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations

PTES · 1 control

  • PTESPHASE-2 Intelligence Gathering (OSINT)
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control

Peru DPL · 1 control

  • PERU-7 DPO, Records, Retention, Marketing, Training

Privacy Act 2020 · 1 control

  • NZPRV-2 IPP 5 Storage and Security of Personal Information

Qatar DPL · 1 control

  • QATAR-5 Security of Processing
  • SHAREASSESS-2 Access Control, Identity, Authentication
  • SOC-CY-S1 Logical and Physical Access Controls

Saudi Arabia PDPL · 1 control

  • SA-PDPL-15 Access control for personal data
  • SIGSTORE-2 Transparency Log (Rekor) and Verification

South Korea PIPA · 1 control

  • PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control

Taiwan PDPA · 1 control

  • TAIWAN-3 Data Subject Rights
  • TEXASTDPSA-2 Consumer Rights

UK Cyber Essentials · 1 control

  • UKGAMBLE-4 Resilience and Incident Response
  • UK-TSA-NET-02 Access Control and Authentication
  • CPSC-CS.2 Authentication and Access Controls
  • US-ITAR-EAR-DS-03 Access Controls

Uruguay DPL · 1 control

  • URUGUAY-3 Sensitive Data, Health Data, Children

Vietnam PDPD · 1 control

  • VIETNAMPDP-2 Consent and Notice

Virginia CDPA · 1 control

  • VIRGINIAVCDPA-3 Sensitive Data Consent and Children

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in AC - Access Control

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-AC-20 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 188 it maps to, and the evidence behind each claim, over MCP and REST.