CMMC 2.0 • LEVEL 1 • ACCESS CONTROL

AC.L1-3.1.20Use of External Systems

Prohibit the use of external systems unless the systems are specifically authorized. Establish the following security requirements to be satisfied on external systems prior to allowing use of or access to those systems by authorized individuals: all systems that store, process, or transmit CUI and all remote access connections used to access CUICMMC/STIG. Permit authorized individuals to use external systems to access the organizational system or to process, store, or transmit CUI only after: Verifying that the security requirements on the external systems as specified in the organization’s system security plans have been satisfied and Retaining approved system connection or processing agreements with the organizational entities hosting the external systems. Restrict the use of organization-controlled portable storage devices by authorized individuals on external systems.

NIST 800-171 Mapping

NIST 800-53 Controls

Assessment Objectives

  • the following security requirements to be satisfied on external systems prior to allowing the use of or access to those systems by authorized individuals are established: all systems that store, process, or transmit CUI and all remote access connections used to access CUICMMC/STIG.
  • the use of external systems is prohibited unless the systems are specifically authorized.
  • authorized individuals are permitted to use external systems to access the organizational system or to process, store, or transmit CUI only after verifying that the security requirements on the external systems as specified in the organization’s system security plans have been satisfied.
  • the use of organization-controlled portable storage devices by authorized individuals on external systems is restricted.
  • authorized individuals are permitted to use external systems to access the organizational system or to process, store, or transmit CUI only after retaining approved system connection or processing agreements with the organizational entity hosting the external systems.

Practitioner Notes

Practitioner commentary coming soon.