CMMC 2.0 • LEVEL 1 • ACCESS CONTROL
AC.L1-3.1.20 — Use of External Systems
Prohibit the use of external systems unless the systems are specifically authorized. Establish the following security requirements to be satisfied on external systems prior to allowing use of or access to those systems by authorized individuals: all systems that store, process, or transmit CUI and all remote access connections used to access CUICMMC/STIG. Permit authorized individuals to use external systems to access the organizational system or to process, store, or transmit CUI only after: Verifying that the security requirements on the external systems as specified in the organization’s system security plans have been satisfied and Retaining approved system connection or processing agreements with the organizational entities hosting the external systems. Restrict the use of organization-controlled portable storage devices by authorized individuals on external systems.
Assessment Objectives
- the following security requirements to be satisfied on external systems prior to allowing the use of or access to those systems by authorized individuals are established: all systems that store, process, or transmit CUI and all remote access connections used to access CUICMMC/STIG.
- the use of external systems is prohibited unless the systems are specifically authorized.
- authorized individuals are permitted to use external systems to access the organizational system or to process, store, or transmit CUI only after verifying that the security requirements on the external systems as specified in the organization’s system security plans have been satisfied.
- the use of organization-controlled portable storage devices by authorized individuals on external systems is restricted.
- authorized individuals are permitted to use external systems to access the organizational system or to process, store, or transmit CUI only after retaining approved system connection or processing agreements with the organizational entity hosting the external systems.
Practitioner Notes
Practitioner commentary coming soon.