Skip to content
ControlVerdict
AC.L2-3.1.20addresses
AC.L2-3.1.20External Connections [CUI Data]
Verify and control/limit connections to and use of external systems.
  • [a]

    connections to external systems are identified;
  • [b]

    the use of external systems is identified;
  • [c]

    connections to external systems are verified;
  • [d]

    the use of external systems is verified;
  • [e]

    connections to external systems are controlled/limited; and

View full control

External system connections via CASB allow-list and reviewed integrations

ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
Community is just starting — add yours. No verdicts yet.

Implementation

AO coverage. Claims objectives [a]–[e] for verifying and limiting connections to external systems that handle CUI. Objective [f] (limit use of portable storage on external systems) is covered under the portable-storage practice example (AC.L2-3.1.21), not duplicated here.

Inventory. Every external system that can receive CUI (partners, ESP tools, subcontractors) is listed with owner, data types, and connection method (API, sync, human upload).

Control. IdP blocks unsanctioned OAuth apps. CASB/DLP blocks upload of labeled CUI to unsanctioned personal cloud. New integrations require security review before client secrets are issued.

Maintenance. Quarterly integration inventory review. Alert on new OAuth grants to enclave users.

Accepted gap. Email to authorized partner domains remains a human path; DLP + encryption mandatory, and partner domain list is contract-owned.

What the evidence looks like

  • External system / integration inventory
  • IdP OAuth app restrictions
  • CASB/DLP policy for unsanctioned cloud
  • Sample approved integration security review

Environment

SaaS-heavy OSC; Microsoft Purview / CASB-class controls.

Tools

Was this example useful?

Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.

Discussion(0)

No discussion on this example yet

Verdicts capture a conclusion. Use a thread when the interesting part is the argument.

Sign in to start a thread.