id: "AC-20(03)" title: "Non-organizationally Owned Systems — Restricted Use" family: "AC" family_name: "Access Control" sort_id: "ac-20.03" priority: "P1" implementation_level: "organization" parent: "AC-20" enhancement: True
Statement
Restrict the use of non-organizationally owned systems or system components to process, store, or transmit organizational information using {{ insert: param, ac-20.03_odp }}.
Guidance
Non-organizationally owned systems or system components include systems or system components owned by other organizations as well as personally owned devices. There are potential risks to using non-organizationally owned systems or components. In some cases, the risk is sufficiently high as to prohibit such use (see AC-20 b. ). In other cases, the use of such systems or system components may be allowed but restricted in some way. Restrictions include requiring the implementation of approved controls prior to authorizing the connection of non-organizationally owned systems and components; limiting access to types of information, services, or applications; using virtualization techniques to limit processing and storage activities to servers or system components provisioned by the organization; and agreeing to the terms and conditions for usage. Organizations consult with the Office of the General Counsel regarding legal issues associated with using personally owned devices, including requirements for conducting forensic analyses during investigations after an incident.
Assessment Objective
the use of non-organizationally owned systems or system components to process, store, or transmit organizational information is restricted using {{ insert: param, ac-20.03_odp }}.
Access control policy
procedures addressing the use of external systems
system design documentation
system configuration settings and associated documentation
system connection or processing agreements
account management documents
system audit records, other relevant documents or records
Organizational personnel with responsibilities for restricting or prohibiting the use of non-organizationally owned systems, system components, or devices
system/network administrators
organizational personnel with information security responsibilities
Mechanisms implementing restrictions on the use of non-organizationally owned systems, components, or devices