# AC-20 Use of External Systems — NIST 800-53 Rev5 control

> FedRAMP Consolidated Rules for 2026 v2026.07.14.01 · updated 2026-07-14
> Canonical page: /control/ac-20

Canonical id: `ac-20` · family `AC`

> a. [assignment], consistent with the trust relationships established with other organizations owning, operating, and/or maintaining external systems, allowing authorized individuals to: 1. Access the system from external systems; and 2. Process, store, or transmit organization-controlled information using external systems; or b. Prohibit the use of [prohibited types of external systems].

_Control title and statement: NIST SP 800-53 Rev5 catalog (the pinned commit is in `/api` under `control_text`). The FedRAMP rules reference these controls by id only; everything below is what FedRAMP says about this id._

## Rev5 baseline membership

- certification class B
- certification class C
- certification class D

## Key Security Indicators that reach it

- `KSI-IAM-ELP` — Ensuring Least Privilege (Identity and Access Management)
  Identity and access management measures are used and persistently reviewed to ensure each user or device can only access the resources they need.
- `KSI-SCR-MIT` — Mitigating Supply Chain Risk (Supply Chain Risk)
  Persistently identify, review, and mitigate potential supply chain risks.
- `KSI-SCR-MON` — Monitoring Supply Chain Risk (Supply Chain Risk)
  Third party software information resources are automatically monitored for upstream vulnerabilities using mechanisms that may include contractual notification requirements or active monitoring services.

## FedRAMP guidance

{
  "guidance": [
    "The interrelated controls of AC-20, CA-3, and SA-9 should be differentiated as follows:",
    "AC-20 describes system access to and from external systems.",
    "CA-3 describes documentation of an agreement between the respective system owners when data is exchanged between the CSO and an external system.",
    "SA-9 describes the responsibilities of external system owners. These responsibilities would typically be captured in the agreement required by CA-3."
  ]
}
