Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon

Browse

98 controls

03.01.20Use of external systemsITSP.10.171Access control

Official Requirement

A. Prohibit the use of external systems unless they are specifically authorized B. Establish the following terms, conditions, and security requirements to be satisfied on external systems prior to allowing use of or access to those systems by authorized individuals: [Assignment: organization-defined security requirements] C. Permit authorized individuals to use an external system to access the organization’s system or to process, store, or transmit specified information only after: 1. verifying that the security requirements on the external system as specified in the organization’s system security and privacy plans have been satisfied 2. retaining approved system connection or processing agreements with the organizational entities hosting the external systems D. Restrict the use of organization-controlled portable storage devices by authorized individuals on external systems

Source: Canadian Centre for Cyber Security ITSP.10.171 (2025), adapted from NIST SP 800-171 Rev. 3

In Plain English

External systems (partner networks, personal devices, third-party SaaS) can only connect to your environment if explicitly authorized. You must verify the external system's security posture, have agreements in place, and restrict how your data (especially on portable storage) is used on those systems.

Help us build what matters.

Vote for the next framework, subscribe for updates, and let us know if you'd contribute.

The Trust Services Criteria referenced in this tool are published by the American Institute of Certified Public Accountants (AICPA) and incorporate principles from the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Criteria descriptions are reproduced for reference purposes. All implementation guidance, evidence recommendations, and control language are original work by Truvo Cyber. ISO 27001 and ISO 42001 are standards published by the International Organization for Standardization (ISO). Framework and standard names are the property of their respective owners. This tool is not affiliated with, endorsed by, or certified by AICPA, COSO, or ISO.

© 2026 Truvo Cyber. All rights reserved.

On-premises implementation and evidence

External system access authorization and controls

Implementation steps

  1. Publish a policy prohibiting use of external systems for organizational data unless explicitly authorized by management
  2. Maintain interconnection security agreements (ISAs) or data processing agreements (DPAs) for each authorized external system connection
  3. Use USB device control policies to restrict portable storage device usage on external systems
  4. Conduct periodic reviews of authorized external connections and revoke those no longer justified

Tools / systems

Evidence artifacts

Evidence frequency: Quarterly external system review; annual agreement renewal