| name | Use of External Systems (03.01.20)_use-of-external-systems |
| description | Prohibit the use of external systems unless the systems are specifically authorized. |
| category | authorization |
| version | 3.0 |
| author | cyberstrike-official |
| tags | ["nist","sp800-171","rev3","use of external systems (03-01-20)","family-03.01","cui-protection","cmmc"] |
| tech_stack | ["aws","azure","gcp","linux","windows"] |
| cwe_ids | ["CWE-284"] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
Use of External Systems (03.01.20) Use of External Systems
High-Level Description
Family: Access Control
Framework: NIST SP 800-171 Rev 3
Applicability: Systems processing, storing, or transmitting CUI
Prohibit the use of external systems unless the systems are specifically authorized.
Establish the following security requirements to be satisfied on external systems prior to allowing use of or access to those systems by authorized individuals: [organization-defined].
Permit authorized individuals to use external systems to access the organizational system or to process, store, or transmit CUI only after:
Verifying that the security requirements on the external systems as specified in the organization’s system security plans have been satisfied and
Retaining approved system connection or processing agreements with the organizational entities hosting the external systems.
Restrict the use of organization-controlled portable storage devices by authorized individuals on external systems.
What to Check
How to Test
Step 1: Review System Security Plan
Examine the SSP for Use of External Systems (03.01.20) implementation description and responsible parties.
Step 2: Assess Implementation
# Verify security controls protecting CUI
# Check access controls, encryption, monitoring as applicable
# For Linux systems:
ls -la /etc/security/ 2>/dev/null
grep -r "CUI\|controlled" /etc/security/ 2>/dev/null
# For cloud:
# Use cloud-audit-mcp tools to assess posture
Step 3: CMMC Assessment Validation
Verify this requirement passes CMMC Level 2 assessment methodology per SP 800-171A Rev 3.
Tools
| Tool | Purpose | Usage |
|---|
| cloud-audit-mcp | Assess cloud CUI environment | cloud_audit_* tools |
| Manual Review | SSP and POA&M review | Documentation analysis |
Remediation Guide