Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-171 CUI Protection Center

03.01.20 — Use of External Systems

Read the official CUI requirement and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect it to implementation, evidence, and sustained operation.

1Parameters
3Source controls
5Assessment objectives
3Assessment methods

03.01 — Access Control · NIST SP 800-171 Revision 3

Active
Official NIST requirement content

Security requirement

  1. a.Prohibit the use of external systems unless the systems are specifically authorized.
  2. b.Establish the following security requirements to be satisfied on external systems prior to allowing use of or access to those systems by authorized individuals: [Organization-defined: security requirements].
  3. c.Permit authorized individuals to use external systems to access the organizational system or to process, store, or transmit CUI only after:
    1. 1.Verifying that the security requirements on the external systems as specified in the organization’s system security plans have been satisfied and
    2. 2.Retaining approved system connection or processing agreements with the organizational entities hosting the external systems.
  4. d.Restrict the use of organization-controlled portable storage devices by authorized individuals on external systems.
Official NIST discussion

Discussion

External systems are systems that are used by but are not part of the organization. These systems include personally owned systems, system components, or devices; privately owned computing and communication devices in commercial or public facilities; systems owned or controlled by nonfederal organizations; and systems managed by contractors. Organizations have the option to prohibit the use of any type of external system or specified types of external systems (e.g., prohibit the use of external systems that are not organizationally owned). Terms and conditions are consistent with the trust relationships established with the entities that own, operate, or maintain external systems and include descriptions of shared responsibilities. Authorized individuals include organizational personnel, contractors, or other individuals with authorized access to the organizational system and over whom organizations have the authority to impose specific rules of behavior regarding system access. Restrictions that organizations impose on authorized individuals may vary depending on the trust relationships between organizations. Organizations need assurance that external systems satisfy the necessary security requirements so as not to compromise, damage, or harm the system. This requirement is related to 03.16.03.

Official organization-defined parameters

Tailoring decisions required

Resolve these values through the governing organization’s approved tailoring and risk-management process before declaring the requirement implemented.

security requirementsorganization-defined security requirementssecurity requirements to be satisfied on external systems prior to allowing the use of or access to those systems by authorized individuals are defined.
Bare Metal Cyber interpretation

Implementation perspective

Treat Use of External Systems as a CUI protection outcome that must be reflected in the system boundary, documented implementation, operational behavior, and assessment evidence. Pay particular attention to approved identities, least privilege, remote access, information flow, and the full account lifecycle.

  1. Confirm the requirement is in scope for the CUI system components, services, users, and external connections being assessed.
  2. Resolve every organization-defined parameter through an approved governance and tailoring process.
  3. Map each clause of the requirement to an accountable owner, implementation mechanism, and evidence source.
  4. Verify that inherited and shared implementations are supported by current provider evidence and responsibility boundaries.
  5. Collect evidence during normal operation and review changes, exceptions, and deficiencies on a risk-based cadence.

Questions to ask

  • Which CUI assets, data flows, users, and services are protected by this requirement?
  • Which portions are implemented locally, inherited, shared, or not applicable, and what evidence supports that determination?
  • Do the system security plan, deployed configuration, operating process, and assessment evidence tell the same story?
  • What change, incident, or threshold should trigger reassessment?

Evidence and validation

  • access authorization and approval records
  • account inventories and entitlement exports
  • access review results
  • authentication and authorization logs

Common failure patterns

  • CUI access that exceeds mission need
  • shared or orphaned accounts
  • remote access paths outside the approved boundary
  • access reviews that cannot be reconciled to deployed permissions
Official NIST SP 800-171A content

Assessment objectives and methods

Assessment objectives (5)
  1. b.

    the following security requirements to be satisfied on external systems prior to allowing the use of or access to those systems by authorized individuals are established: [Organization-defined: security requirements].

  2. a.

    the use of external systems is prohibited unless the systems are specifically authorized.

  3. c.1.

    authorized individuals are permitted to use external systems to access the organizational system or to process, store, or transmit CUI only after verifying that the security requirements on the external systems as specified in the organization’s system security plans have been satisfied.

  4. d.

    the use of organization-controlled portable storage devices by authorized individuals on external systems is restricted.

  5. c.2.

    authorized individuals are permitted to use external systems to access the organizational system or to process, store, or transmit CUI only after retaining approved system connection or processing agreements with the organizational entity hosting the external systems.

Examine

  • access control policy and procedures
  • procedures for the use of external systems
  • terms and conditions for the use of external systems
  • external systems security requirements
  • list of types of applications accessible from external systems
  • system configuration settings
  • system security plan
  • other relevant documents or records

Interview

  • personnel with responsibilities for defining terms, conditions, and security requirements for the use of external systems
  • personnel with information security responsibilities
  • system administrators

Test

  • mechanisms for implementing or enforcing terms, conditions, and security requirements for the use of external systems
Official source-control relationships

Source NIST SP 800-53 controls

These controls are referenced by the official SP 800-171 Rev. 3 OSCAL record. Open the corresponding control pages for complete control text, enhancements, D3FEND mappings, and related learning.

Source record

Authoritative sources