PlumbTrackLive demoGRC Risk System

← control library

Use of External Systems AC-20

Access Control · Low baseline ✗ Not implemented

Status — program-wide

What references this control

No risks name this control in their Framework field yet.

No policies reference it yet.


Link a risk or policy to this control

Attaching adds AC-20 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.

Source: NIST SP 800-53 Rev.5, Access Control family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.

Control guide — plain-English, per NIST SP 800-53

AC-20 (Use of External Systems) is about setting the rules for systems you do not own or control — an administrator’s home laptop, a contractor’s machine, a public kiosk, or a cloud service — when those systems connect to this server or handle its information. Under the control you do one of two things for each type: establish written terms and conditions for using it, or prohibit it outright. It sits in the Low baseline as a foundational Access Control.

What good looks like

Framework mapping

How to move it toward Implemented