{"data":{"id":"AC-20","name":"Use of External Systems","family":"AC","family_name":"Access Control","withdrawn":false,"description":"a. [Selection (one or more): Establish [Assignment: organization-defined terms and conditions]; Identify [Assignment: organization-defined controls asserted to be implemented on external systems]], consistent with the trust relationships established with other organizations owning, operating, and/or maintaining external systems, allowing authorized individuals to:\n1. Access the system from external systems; and\n2. Process, store, or transmit organization-controlled information using external systems; or\nb. Prohibit the use of [Assignment: organizationally-defined types of external systems].","supplemental_guidance":"External systems are systems that are used by but not part of organizational systems, and for which the organization has no direct control over the implementation of required controls or the assessment of control effectiveness. External systems include personally owned systems, components, or devices; privately owned computing and communications devices in commercial or public facilities; systems owned or controlled by nonfederal organizations; systems managed by contractors; and federal information systems that are not owned by, operated by, or under the direct supervision or authority of the organization. External systems also include systems owned or operated by other components within the same organization and systems within the organization with different authorization boundaries. Organizations have the option to prohibit the use of any type of external system or prohibit the use of specified types of external systems, (e.g., prohibit the use of any external system that is not organizationally owned or prohibit the use of personally-owned systems).\n\nFor some external systems (i.e., systems operated by other organizations), the trust relationships that have been established between those organizations and the originating organization may be such that no explicit terms and conditions are required. Systems within these organizations may not be considered external. These situations occur when, for example, there are pre-existing information exchange agreements (either implicit or explicit) established between organizations or components or when such agreements are specified by applicable laws, executive orders, directives, regulations, policies, or standards. Authorized individuals include organizational personnel, contractors, or other individuals with authorized access to organizational systems and over which organizations have the authority to impose specific rules of behavior regarding system access. Restrictions that organizations impose on authorized individuals need not be uniform, as the restrictions may vary depending on trust relationships between organizations. Therefore, organizations may choose to impose different security restrictions on contractors than on state, local, or tribal governments.\n\nExternal systems used to access public interfaces to organizational systems are outside the scope of AC-20. Organizations establish specific terms and conditions for the use of external systems in accordance with organizational security policies and procedures. At a minimum, terms and conditions address the specific types of applications that can be accessed on organizational systems from external systems and the highest security category of information that can be processed, stored, or transmitted on external systems. If the terms and conditions with the owners of the external systems cannot be established, organizations may impose restrictions on organizational personnel using those external systems.","enhancements":[{"id":"AC-20(01)","name":"Limits on Authorized Use","statement":"Permit authorized individuals to use an external system to access the system or to process, store, or transmit organization-controlled information only after:\na. Verification of the implementation of controls on the external system as specified in the organization’s security and privacy policies and security and privacy plans; or\nb. Retention of approved system connection or processing agreements with the organizational entity hosting the external system.","baselines":["moderate","high"]},{"id":"AC-20(02)","name":"Portable Storage Devices — Restricted Use","statement":"Restrict the use of organization-controlled portable storage devices by authorized individuals on external systems using [Assignment: organization-defined restrictions].","baselines":["moderate","high"]},{"id":"AC-20(03)","name":"Non-organizationally Owned Systems — Restricted Use","statement":"Restrict the use of non-organizationally owned systems or system components to process, store, or transmit organizational information using [Assignment: organization-defined restrictions].","baselines":[]},{"id":"AC-20(04)","name":"Network Accessible Storage Devices — Prohibited Use","statement":"Prohibit the use of [Assignment: organization-defined network accessible storage devices] in external systems.","baselines":[]},{"id":"AC-20(05)","name":"Portable Storage Devices — Prohibited Use","statement":"Prohibit the use of organization-controlled portable storage devices by authorized individuals on external systems.","baselines":[]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"AC-20","name":"Use of External Systems","description":"a. [Selection (one or more): Establish [Assignment: organization-defined terms and conditions]; Identify [Assignment: organization-defined controls asserted to be implemented on external systems]], consistent with the trust relationships established with other organizations owning, operating, and/or maintaining external systems, allowing authorized individuals to:\n1. Access the system from external systems; and\n2. Process, store, or transmit organization-controlled information using external systems; or\nb. Prohibit the use of [Assignment: organizationally-defined types of external systems].","discussion":"External systems are systems that are used by but not part of organizational systems, and for which the organization has no direct control over the implementation of required controls or the assessment of control effectiveness. External systems include personally owned systems, components, or devices; privately owned computing and communications devices in commercial or public facilities; systems owned or controlled by nonfederal organizations; systems managed by contractors; and federal information systems that are not owned by, operated by, or under the direct supervision or authority of the organization. External systems also include systems owned or operated by other components within the same organization and systems within the organization with different authorization boundaries. Organizations have the option to prohibit the use of any type of external system or prohibit the use of specified types of external systems, (e.g., prohibit the use of any external system that is not organizationally owned or prohibit the use of personally-owned systems).\n\nFor some external systems (i.e., systems operated by other organizations), the trust relationships that have been established between those organizations and the originating organization may be such that no explicit terms and conditions are required. Systems within these organizations may not be considered external. These situations occur when, for example, there are pre-existing information exchange agreements (either implicit or explicit) established between organizations or components or when such agreements are specified by applicable laws, executive orders, directives, regulations, policies, or standards. Authorized individuals include organizational personnel, contractors, or other individuals with authorized access to organizational systems and over which organizations have the authority to impose specific rules of behavior regarding system access. Restrictions that organizations impose on authorized individuals need not be uniform, as the restrictions may vary depending on trust relationships between organizations. Therefore, organizations may choose to impose different security restrictions on contractors than on state, local, or tribal governments.\n\nExternal systems used to access public interfaces to organizational systems are outside the scope of AC-20. Organizations establish specific terms and conditions for the use of external systems in accordance with organizational security policies and procedures. At a minimum, terms and conditions address the specific types of applications that can be accessed on organizational systems from external systems and the highest security category of information that can be processed, stored, or transmitted on external systems. If the terms and conditions with the owners of the external systems cannot be established, organizations may impose restrictions on organizational personnel using those external systems.","related_controls":["AC-02","AC-03","AC-17","AC-19","CA-03","PL-02","PL-04","SA-09","SC-07"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"Title changed from 'Use of External Information Systems' Added parameter incorporates original text into a selection list  Added parameter defines external systems prohibited from use  Discussion adds reference to privacy and expands on organizational options regarding use or prohibition of external systems"}},"compliance_mappings":{"iso_27001_2022":["A.5.10","A.5.14","A.5.23","A.7.9","A.8.20"],"iso_27002_2022":["5.10","5.14","5.23"],"cobit_2019":["DSS05"],"pci_dss_v4":["1.5","12.2"],"nist_csf_2":["ID.AM-02","ID.AM-04"],"cis_controls_v8":["CIS 13.5"],"soc2_tsc":["CC6.7"],"finos_ccc":["CCC-C05"],"iso_42001_2023":["A.10.2"],"iec_62443":[],"asd_e8":[],"nis2":["Art. 21(2)(i)"],"apra_cps_234":[],"mas_trm":["9"],"pra_op_resilience":["SS2/21-9.1","SS2/21-14.1"],"bsi_grundschutz":["ORP.4"],"anssi":["Hygiene.9","Hygiene.22","SecNumCloud.16.1"],"osfi_b13":["B-13.3.2","B-13.4.1"],"finma_circular":["IV.B.d(59)","IV.F(100)","V(101)"],"gdpr":["Art.28(1)","Art.28(3)(a)","Art.32(1)(b)"],"dora":["Art.28(1)(a)","Art.28(5)"],"bio2":["5.10","5.14","5.23"],"rbi_csf":["Annex1.8","ITGRCA.20"],"fisc":["FISC.O6","FISC.T9","FISC.T13"],"lgpd_bcb":["BCB.Art.11"],"hkma_tme1":["TME1.8.5","TME1.12.4"],"mlps_2":["8.1.3.1"],"dnb_good_practice":[],"cra":[],"swift_cscf":["SWIFT.1.4"],"cbb_tm":["TM-6","TM-15"],"cbuae":["CR-4"],"nca_ecc":["2-6","4-2"],"qatar_nia":["AC","CS"],"sama_csf":["3.8","4.3"],"uae_ia":["T8","T9"],"bog_cisd":["CISD-VIII","CISD-XI","CISD-XII","CISD-XIII"],"bom_ctrm":["3.2"],"cbe_csf":["CTO-1","CTO-11"],"cbn_csf":["Part2.4","Part3.2"],"sa_js2":["JS2-7.1"],"bcbs_239":["Principle 14"],"bot_cyber":["Ch2.6","Ch5.2"],"cpmi_pfmi":["CG.PR"],"eba_ict":["3.2.3"],"ecb_croe":["CROE.2.2.3"],"ffiec_is":["II.C.6","II.C.13(e)","II.C.15(c)","II.C.16"],"hipaa_sr":["§164.310(b)"],"iosco_cyber":["PFMI-20"],"nydfs_500":["500.7","500.11"],"sebi_cscrf":["PR.CS"],"cmmc_2":["AC"],"nerc_cip":["CIP-005-7"],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":["Sec 5.3"],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":["Clause 7","Clause 8"],"fca_sysc_13":["SYSC 13.7.3"],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":["01.b","01.d","05.c"],"iso_27799":["6.3","8.3","13.2","15.2","H.2"],"lloyds_ms":["MS6.1","MS8.3","MS13.1"],"naic_ds":["4-access","4D"],"nhs_dspt":["NDG-9.7"],"pra_ss1_23":[],"solvency_ii":["Art.49(1)","DR.272","EIOPA-Cloud-GL3"],"owasp_masvs_v2":[],"csa_ccm_v4":["HRS-02","UEM-14"],"csa_aicm":["HRS-02","UEM-14"],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":["SEC-CD-10"],"dpdpa":[]},"attack_techniques":[{"id":"T1021","name":"Remote Services","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Establishing terms and conditions for external system access ensures that remote service connections from uncontrolled devices meet minimum security requirements, limiting lateral movement from compromised external systems."},{"id":"T1041","name":"Exfiltration Over C2 Channel","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Restricting the types of data that can be accessed from external systems and enforcing data classification controls limits the sensitivity of information adversaries can exfiltrate over C2 channels from external devices."},{"id":"T1048","name":"Exfiltration Over Alternative Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Establishing controls for external system connectivity and restricting outbound data flows from unmanaged devices limits adversaries' ability to exfiltrate data through alternative protocols from external systems."},{"id":"T1052","name":"Exfiltration Over Physical Medium","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Policies governing external system use that restrict data transfer to removable media from unmanaged devices prevent adversaries from using external systems to exfiltrate data via physical media."},{"id":"T1072","name":"Software Deployment Tools","tactics":["execution","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Restricting the use of external systems for software deployment and requiring managed devices for administrative tasks prevents adversaries from using uncontrolled devices to access deployment tools."},{"id":"T1110","name":"Brute Force","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Enforcing strong authentication requirements for access from external systems including MFA and certificate-based authentication limits the effectiveness of brute force attacks from unmanaged devices."},{"id":"T1111","name":"Multi-Factor Authentication Interception","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Requiring organization-controlled MFA tokens for external system access and prohibiting software-based authenticators on unmanaged devices limits adversaries' ability to intercept multi-factor authentication."},{"id":"T1114","name":"Email Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Restricting email access from external systems and enforcing conditional access policies for mail services prevents adversaries from using unmanaged devices to collect email from organizational mailboxes."},{"id":"T1119","name":"Automated Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Restricting external system access to only designated applications and data categories limits the scope of automated collection adversaries can perform from compromised external devices."},{"id":"T1133","name":"External Remote Services","tactics":["initial-access","persistence"],"mapping_type":"mitigates","mapping_rationale":"Establishing security requirements for external remote service access ensures that VPN and remote desktop connections from unmanaged devices meet organizational security baselines before granting access."},{"id":"T1136","name":"Create Account","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Restricting account creation capabilities from external systems ensures that adversaries accessing from uncontrolled devices cannot establish new accounts for persistent access."},{"id":"T1200","name":"Hardware Additions","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Policies governing the use of external hardware and establishing verification procedures for devices connecting to organizational networks prevent adversaries from introducing malicious hardware additions."},{"id":"T1530","name":"Data from Cloud Storage","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Restricting cloud storage access from external systems and enforcing device compliance checks for cloud service access prevents unauthorized devices from accessing organizational cloud data."},{"id":"T1537","name":"Transfer Data to Cloud Account","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Restricting cross-account cloud operations from external systems prevents adversaries using compromised external devices from transferring organizational data to unauthorized cloud accounts."},{"id":"T1539","name":"Steal Web Session Cookie","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Enforcing session token restrictions for external system access and requiring re-authentication from unmanaged devices limits adversaries' ability to steal and reuse web session cookies."},{"id":"T1552","name":"Unsecured Credentials","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Restricting credential access from external systems and prohibiting credential caching on unmanaged devices limits the unsecured credential material adversaries can harvest from external endpoints."},{"id":"T1555","name":"Credentials from Password Stores","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Prohibiting organizational credential storage on external systems and enforcing just-in-time credential provisioning prevents adversaries from extracting saved passwords from unmanaged devices."},{"id":"T1556","name":"Modify Authentication Process","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Requiring organization-managed authentication mechanisms for external system access prevents adversaries from exploiting modified authentication processes on uncontrolled devices."},{"id":"T1557","name":"Adversary-in-the-Middle","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Enforcing encrypted communications and certificate validation for external system connections prevents adversaries from intercepting traffic between external devices and organizational resources."},{"id":"T1565","name":"Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Restricting write access to organizational data from external systems and enforcing data integrity controls limits adversaries' ability to manipulate organizational data through compromised external devices."},{"id":"T1567","name":"Exfiltration Over Web Service","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Restricting external system access to authorized cloud services and enforcing DLP policies on external connections limits exfiltration of organizational data through web services."},{"id":"T1602","name":"Data from Configuration Repository","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Restricting network device management from external systems ensures that adversaries cannot access device configuration data from uncontrolled endpoints outside the managed environment."},{"id":"T1020.001","name":"Traffic Duplication","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Restricting network management capabilities from external systems prevents adversaries from configuring traffic duplication through compromised external devices with network access."},{"id":"T1021.001","name":"Remote Desktop Protocol","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Enforcing conditional access policies for RDP connections from external systems ensures unmanaged devices meet security requirements before establishing remote desktop sessions."},{"id":"T1021.004","name":"SSH","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Requiring certificate-based SSH authentication from external systems and restricting key-based access to managed devices prevents unauthorized SSH lateral movement from external endpoints."},{"id":"T1021.007","name":"Cloud Services","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Enforcing device compliance requirements for cloud service access prevents adversaries from using compromised external systems to access organizational cloud resources for lateral movement."},{"id":"T1021.008","name":"Direct Cloud VM Connections","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Restricting direct cloud VM access from external systems and requiring bastion host connections ensures external devices cannot directly reach cloud compute infrastructure."},{"id":"T1048.002","name":"Exfiltration Over Asymmetric Encrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Restricting outbound encrypted data transfers from external systems through conditional access and DLP policies limits exfiltration over asymmetric encrypted non-C2 protocols."},{"id":"T1048.003","name":"Exfiltration Over Unencrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Enforcing encryption requirements for data in transit from external systems and blocking unencrypted outbound protocols prevents cleartext exfiltration from unmanaged devices."},{"id":"T1052.001","name":"Exfiltration over USB","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Prohibiting USB data transfer from external systems and enforcing device control policies for unmanaged endpoints prevents adversaries from exfiltrating data via USB from external devices."},{"id":"T1070.008","name":"Clear Mailbox Data","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Restricting mailbox administration capabilities from external systems prevents adversaries from clearing mailbox data and evidence through unmanaged devices."},{"id":"T1078.002","name":"Domain Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Enforcing conditional access policies that evaluate device compliance for domain account authentication limits adversaries' ability to use stolen domain credentials from external systems."},{"id":"T1078.004","name":"Cloud Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Requiring device enrollment and compliance verification for cloud account access prevents adversaries from using compromised cloud credentials from unmanaged external devices."},{"id":"T1098.001","name":"Additional Cloud Credentials","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Restricting cloud credential management from external systems prevents adversaries from adding unauthorized API keys or certificates through uncontrolled devices."},{"id":"T1098.002","name":"Additional Email Delegate Permissions","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Restricting email delegation configuration from external systems prevents adversaries from establishing email forwarding rules through compromised unmanaged devices."},{"id":"T1098.003","name":"Additional Cloud Roles","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Restricting cloud role management from external systems ensures adversaries cannot escalate privileges by assigning additional cloud roles through uncontrolled devices."},{"id":"T1098.004","name":"SSH Authorized Keys","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Restricting SSH key management from external systems prevents adversaries from injecting authorized keys into organizational servers through compromised external devices."},{"id":"T1098.005","name":"Device Registration","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Restricting device registration capabilities from external systems prevents adversaries from enrolling unauthorized devices to gain compliant access to organizational resources."},{"id":"T1110.001","name":"Password Guessing","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Enforcing enhanced authentication controls (MFA, CAPTCHA, rate limiting) for access from external systems limits the effectiveness of password guessing attacks from unmanaged devices."},{"id":"T1110.002","name":"Password Cracking","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Requiring strong authentication from external systems ensures that even if password hashes are obtained, they cannot be easily cracked for external system access."},{"id":"T1110.003","name":"Password Spraying","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Implementing intelligent lockout and anomaly detection for external system authentication detects and blocks password spraying campaigns originating from uncontrolled devices."},{"id":"T1110.004","name":"Credential Stuffing","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Enforcing MFA for all external system access ensures that credential stuffing attacks using stolen credentials fail without the second authentication factor."},{"id":"T1114.001","name":"Local Email Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Restricting local email client configurations on external systems through conditional access prevents adversaries from collecting email through unmanaged mail applications."},{"id":"T1114.002","name":"Remote Email Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Enforcing conditional access policies for remote email protocols prevents unauthorized external devices from connecting to mail servers for email collection."},{"id":"T1114.003","name":"Email Forwarding Rule","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Restricting email rule configuration from external systems prevents adversaries from establishing email forwarding rules through compromised unmanaged endpoints."},{"id":"T1134.005","name":"SID-History Injection","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Restricting directory service access from external systems prevents adversaries from exploiting SID-History injection through compromised uncontrolled devices."},{"id":"T1136.001","name":"Local Account","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Prohibiting local account creation from external system sessions prevents adversaries from establishing persistent local accounts through unmanaged devices."},{"id":"T1136.002","name":"Domain Account","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Restricting domain account creation from external systems ensures adversaries cannot provision rogue domain accounts through compromised uncontrolled devices."},{"id":"T1136.003","name":"Cloud Account","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Restricting cloud account provisioning from external systems prevents adversaries from creating persistent cloud accounts through compromised external endpoints."},{"id":"T1505.005","name":"Terminal Services DLL","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Restricting Terminal Services administration from external systems prevents adversaries from installing malicious RDP-related DLLs through unmanaged devices."},{"id":"T1550.001","name":"Application Access Token","tactics":["defense-evasion","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Enforcing application token validation and device compliance checks for API access prevents adversaries from using stolen application tokens from external systems."},{"id":"T1552.004","name":"Private Keys","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Prohibiting private key storage on external systems and enforcing hardware security module usage for cryptographic operations prevents key theft from unmanaged devices."},{"id":"T1552.005","name":"Cloud Instance Metadata API","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Restricting cloud instance metadata access from external systems and enforcing IMDSv2 prevents adversaries from harvesting cloud credentials through unmanaged endpoints."},{"id":"T1556.001","name":"Domain Controller Authentication","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Restricting domain controller access from external systems through network segmentation and conditional access prevents authentication infrastructure modification from unmanaged devices."},{"id":"T1556.003","name":"Pluggable Authentication Modules","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Restricting PAM configuration access from external systems prevents adversaries from modifying pluggable authentication modules through compromised uncontrolled devices."},{"id":"T1556.004","name":"Network Device Authentication","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Restricting network device authentication management from external systems prevents adversaries from modifying TACACS+ or RADIUS settings through unmanaged endpoints."},{"id":"T1557.002","name":"ARP Cache Poisoning","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Restricting network access from external systems and enforcing network admission controls prevents adversaries from performing ARP cache poisoning attacks from unmanaged devices."},{"id":"T1565.001","name":"Stored Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Restricting write access to organizational data stores from external systems prevents adversaries from manipulating stored data through compromised unmanaged devices."},{"id":"T1565.002","name":"Transmitted Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Enforcing encrypted communications and integrity verification for external system connections prevents adversaries from manipulating data in transit from uncontrolled devices."},{"id":"T1567.001","name":"Exfiltration to Code Repository","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Restricting access to code repositories from external systems and enforcing repository access policies prevents data exfiltration through code hosting platforms from unmanaged devices."},{"id":"T1567.002","name":"Exfiltration to Cloud Storage","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Restricting cloud storage uploads from external systems through DLP and conditional access policies prevents data exfiltration to cloud storage services from unmanaged endpoints."},{"id":"T1578.005","name":"Modify Cloud Compute Configurations","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Restricting cloud compute configuration changes from external systems prevents adversaries from modifying cloud instance settings through compromised unmanaged devices."},{"id":"T1602.001","name":"SNMP (MIB Dump)","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Restricting SNMP management from external systems prevents adversaries from performing MIB dumps to extract network device configurations from uncontrolled endpoints."},{"id":"T1602.002","name":"Network Device Configuration Dump","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Restricting device configuration management from external systems prevents adversaries from dumping network device configurations through compromised unmanaged devices."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: iso_27001_2022 A.7.9, A.8.20 added from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR entry 155), which OSA's mapping now takes as its base. 2026-10-03: nist_csf_2 ID.AM-02, ID.AM-04 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-013","SP-015","SP-019","SP-021","SP-022","SP-025","SP-029","SP-030","SP-046"]}}