Frameworks / NIST SP 800-53 Rev 5 / NIST800-AC-20 NIST SP 800-53 Rev 5
AC - Access Control
NIST SP 800-53 Rev 5 NIST800-AC-20: AC-20 Use of External Systems a. [Selection (one or more): establish [Assignment: organization-defined terms and conditions]; identify [Assignment: organization-defined controls asserted to be implemented on external systems]], consistent with the trust relationships established with other organizations owning, operating, and/or maintaining external systems, allowing authorized individuals to: 1. Access the system from external systems; and 2. Process, store, or transmit organization-controlled information using external systems; or b. Prohibit the use of [Assignment: organizationally-defined types of external systems].
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 188 controls across 95 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
1.4.1 1.4.1 NSCs between trusted and untrusted networks 1.5.1 1.5.1 Security controls on dual-connected devices 12.8.2 12.8.2 TPSP contracts acknowledging account data responsibility 12.8.3 12.8.3 Due diligence before engaging TPSPs 12.8.4 12.8.4 Annual monitoring of TPSP compliance status 8.2.7 8.2.7 Third-party remote access accounts controlled SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary SOC2-CC9.2 CC9.2 Assessing and managing vendor and business partner risk SOC2-P6.4 P6.4 Privacy commitments from vendors and third parties SOC2-P6.5 P6.5 Vendor commitments to report unauthorised disclosures AC-20 Use of External Systems AC-20(1) Limits on Authorized Use AC-20(2) Portable Storage Devices Restricted Use PL-4(1) Rules of Behavior | Social Media and External Site/Application Usage Restrictions (PL-4(1)) AC-20 Use of External Systems AC-20(1) Limits on Authorized Use AC-20(2) Portable Storage Devices Restricted Use PL-4(1) Rules of Behavior | Social Media and External Site/Application Usage Restrictions (PL-4(1)) 6.10.2 Information transfer 6.12.1 Information security in supplier relationships 6.6.2 User access management 6.9.4 Logging and monitoring API1164-06 Access Control API1164-07 Remote Access API1164-09 Patch and Vulnerability Management BSI-03 Multi-factor authentication requirements BSI-04 Remote access controls BSI-05 Wireless access restrictions IEC62443-07 Personnel risk assessment IEC62443-08 Electronic access perimeter management IEC62443-10 Revocation of access procedures 5.20 Addressing information security within supplier agreements 5.22 Monitoring, review and change management of supplier services 5.23 Information security for use of cloud services ISO27799-01 ePHI access controls and authorization ISO27799-08 Information access management ISO27799-17 Facility access controls ISO27019-07 Personnel risk assessment ISO27019-08 Electronic access perimeter management ISO27019-10 Revocation of access procedures ISO27043-11 Access control policy and enforcement ISO27043-14 Privileged access management ISO27043-15 Access review and recertification ISO21434-12 User access management and provisioning ISO21434-14 Privileged access management ISO21434-15 Access review and recertification ANSSI-HYG-07 Authorise Network Connection Only for Managed Equipment ANSSI-HYG-25 Secure Dedicated Network Interconnections with Partners AWWA-2.1 User Access Management AWWA-2.4 Physical Access Controls AM-2 Use only approved services ASBv3-PA-8 Determine access process for cloud provider support DSO-2 Data Security DSO-3 Data Access Management CAT-D3-1 Preventative controls CAT-D4-3 Third-party access controls 27010-9.1 Access Control to Shared Information 27010-9.2 Authentication of Sources 27011-5.3 Segregation of duties 27011-8.1 User Endpoint Devices 161R1-AC-20 Use of External Systems 161R1-PM-17 Protecting Controlled Unclassified Information on External Systems SUPCHAIN-1 Build Integrity - Source, Build, Provenance SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule ISMSP-AC-01 Access Control Policy ISMSP-AC-04 Network Access Control APPI-A26 Report of Leakage to the Commission and Notification to the Person SEC03-BP09 Share resources securely with a third party C5-SSO-01 Policies and instructions for controlling and monitoring third parties CIS-4.12 Separate Enterprise Workspaces on Mobile End-User Devices CA-ITSG33-SC-01 Security Control Catalogue FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7) IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18) 62351-8 Role-based access control (RBAC) 5.23 Information security for use of cloud services ISO28001-PS-01 Facility Security ISO20000-15 Access management for services ITIL4-15 Access management for services NIST-CSF-GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties NISTPF-5 Protect-P Access Control (PR.AC-P) 3.1.2e Restrict Access to Organization-Owned, Provisioned, or Issued Information Resources AC-20 AC-20 Use of External Systems AC-20 AC-20 Use of External Systems AC-20 AC-20 Use of External Systems NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OMANCS-3 Identity and Access Management, Authentication, Privileged Access OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working PDPASG-5 Protection, Accuracy, and Security of Personal Data PDPATH-5 Security Measures and Data Protection POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations PTESPHASE-2 Intelligence Gathering (OSINT) NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control PERU-7 DPO, Records, Retention, Marketing, Training NZPRV-2 IPP 5 Storage and Security of Personal Information QATAR-5 Security of Processing SHAREASSESS-2 Access Control, Identity, Authentication SOC-CY-S1 Logical and Physical Access Controls SA-PDPL-15 Access control for personal data SIGSTORE-2 Transparency Log (Rekor) and Verification PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021 TSAPIPE-2 OT/IT Network Segmentation and Access Control TAIWAN-3 Data Subject Rights TEXASTDPSA-2 Consumer Rights UKGAMBLE-4 Resilience and Incident Response SEMD-PS-2 Site Security Measures UK-TSA-NET-02 Access Control and Authentication CPSC-CS.2 Authentication and Access Controls US-ITAR-EAR-DS-03 Access Controls URUGUAY-3 Sensitive Data, Health Data, Children VIETNAMPDP-2 Consent and Notice VIRGINIAVCDPA-3 Sensitive Data Consent and Children Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in AC - Access Control You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done? NIST SP 800-53 Rev 5 NIST800-AC-20 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 188 it maps to, and the evidence behind each claim, over MCP and REST.