1Overview
AC.L2-3.1.20 governs the seam between the organization's environment and the systems it does not control. It requires that connections to and use of external systems be verified and either controlled or limited, so that the boundary of the CUI environment is not quietly extended through every outside system an employee happens to use. It is one of the controls that cannot remain open on a plan of action at a Level 2 assessment.
An external system is one outside the organization's authorization boundary: a home computer, a partner's network, a personal cloud account, a kiosk, a device the organization neither owns nor manages. The risk is that CUI flows to or through these systems, or that these systems connect into the environment, without any assurance about how they are secured. The control asks the organization to know where its environment connects to the outside, to verify that those external systems meet its requirements or to limit what they can do, and specifically to govern the use of the organization's own cloud and external services and the portable storage that moves between inside and outside. It is a boundary control as much as an access control, and it interacts closely with the scoping that defines the environment in the first place.
Verify and control or limit connections to and use of external systems.
The requirement pairs "verify" with "control or limit." To verify is to have assurance that an external system meets the organization's security requirements before it connects or is used for CUI. To control or limit is either to permit the connection under conditions the organization enforces, or, where that assurance is not possible, to limit or prohibit the use. The requirement also reaches the organization's use of external systems, including cloud services, and the connection of portable storage to external systems, drawing those specific cases into the control.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.1.20 into six objectives: identify the external connections and their use, verify each, and control or limit each.
Connections to external systems are identified. The organization knows where its environment connects to systems outside its boundary.
The use of external systems is identified. The organization knows how external systems are used in relation to CUI, including its own cloud services and staff use of outside systems.
Connections to external systems are verified. The organization has assurance that the external systems it connects to meet its security requirements.
The use of external systems is verified. The organization has assurance that the external services used for CUI meet its requirements, including its own cloud services.
Connections to external systems are controlled/limited. Connections that cannot be assured are limited or prohibited.
The use of external systems is controlled/limited. Use of external systems for CUI that cannot be assured is limited or prohibited, and the limit is enforced.
The six objectives pair identification, verification, and control across both connection and use. The common gap is at objectives [c] through [f], where an organization identifies its external systems but neither verifies the important ones nor limits the ones it cannot verify, so external systems of unknown security posture continue to touch CUI. The assessor looks for verification of the trusted external systems and a real limit on the rest.
3Failure Patterns
The failures are about CUI leaving onto systems the organization does not control and about external services adopted without verification.
Work on personal home computers
Staff working on CUI from personal home computers place controlled data on systems the organization has no assurance about, which fails objectives [c] and [d] directly. The resolution is either to bring that work onto managed devices or a verified virtual environment, or to prohibit and prevent it, since a personal home computer of unknown security cannot be verified.
Consumer cloud and personal accounts
Personal cloud storage, personal email, and consumer file-sharing used for work move CUI onto external systems outside any organizational control. The control requires that use of external systems for CUI be verified or limited, and consumer services used ad hoc are neither, so they have to be replaced with sanctioned services or blocked.
Cloud services adopted without verification
Even sanctioned cloud services are external systems, and adopting one to handle CUI without verifying it meets the requirements, including the specific assurance expected for cloud handling CUI, fails the verification element. The organization has to confirm that an external service is adequate before entrusting CUI to it, not merely that it is convenient or widely used.
Portable storage across the boundary
The requirement specifically reaches the connection of portable storage to external systems, so a thumb drive that carries CUI and is then plugged into a home computer or an external system crosses the boundary in a way this control governs. Portable storage used without limits is a path for CUI onto unverified external systems, and it connects to the media protection family.
4Ownership
This control spans IT enforcement, a leadership decision about remote and personal-system use, and the verification of external services, so its ownership is broader than a single technical setting.
| Role | Responsibility for this control |
|---|---|
| IT and system administrator | Identifies external connections and use, enforces the limits on personal systems and consumer services, and controls portable storage crossing the boundary. Owns the technical evidence. |
| Security or compliance lead | Verifies that trusted external systems and cloud services meet the requirements before CUI is entrusted to them, and defines what use is prohibited. |
| Executive sponsor | Decides the posture on personal systems and remote work, since prohibiting work on personal home computers is a business decision that leadership has to make and support. |
| Program lead | Includes external systems and services in periodic review, since new cloud services and connections appear continually, and retains the verification records. |
5Tooling
The control is built with the boundary and cloud controls that limit external connections and use, plus the verification records that assure the trusted external systems.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a], [b] | Connection and service inventory, cloud discovery | Identification of where the environment connects externally and which external services are used for CUI, including discovery of unsanctioned cloud use. |
| [e], [f] control | Conditional Access, firewall and DLP egress controls, web filtering | Confining CUI to verified external systems, blocking consumer cloud and personal accounts, and limiting connections to those that are assured. |
| [c], [d] verification | Cloud service assessment, FedRAMP or equivalent assurance for cloud handling CUI | Confirming that external services entrusted with CUI meet the required security posture before use. |
| Portable storage and personal systems | Removable-media controls, virtual desktop or managed access for remote work | Limiting portable storage across the boundary and providing a verified path for remote work instead of personal home computers. |
The caveat is that verification and limitation are alternatives the organization must actually choose between for each external system, not a box to check. Where an external system can be verified to meet requirements, it may be used under control; where it cannot, its use must be limited or prohibited and that limit enforced. The assessor tests objectives [c] and [d] by examining whether CUI can reach an unverified external system, such as a personal cloud account or home computer, so the enforcement has to close those paths while permitting the verified ones.
6Evidence
The satisfied version of 3.1.20 shows the identified external systems, the verification of the trusted ones, and the enforced limits on the rest.
| Evidence | What it demonstrates |
|---|---|
| External connection and service inventory | Objectives [a], [b]. The identified external connections and the external systems used for CUI. |
| External system verification records | Objectives [c], [d]. Evidence that trusted external systems and cloud services meet the requirements before CUI is entrusted to them. |
| External access control configuration | Objectives [e], [f]. The controls confining CUI to verified systems and blocking consumer and personal external systems. |
| Remote work and personal-system policy | Objective [f]. The enforced posture on personal home computers and the verified alternative provided. |
| Portable storage controls | Objective [e]. Limits on portable storage crossing to external systems. |
The evidence should show both that trusted external systems are verified and that unverified ones are limited or blocked, since the control turns on that pairing. Demonstrating that CUI cannot reach a personal cloud account or home computer, while the sanctioned external services are documented as verified, is the clearest demonstration, and because this control cannot sit on a plan of action, the enforcement has to be real at the time of assessment.
The boundary is only real if the outside is closed
External systems are where a carefully drawn boundary quietly leaks, through the home computer, the personal cloud account, the unverified service, the traveling thumb drive. Deciding the posture on personal systems, verifying the external services that handle CUI, and closing the rest is part of the onsite readiness work this practice does, and it is one of the controls that must be closed rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.1.20. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.1.20[a] through 3.1.20[f]. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov