home/glossary/External Information System or Component

External Information System or Component

nounid 2537·updated May 9, 2026
candidate

An information system or component of an information system that is outside of the authorization boundary established by the organization and for which the organization typically has no direct control over the application of required security controls or the assessment of security control effectiveness.

MWE

Classifications

Entity Type

System95%llm-generatedllm:claude-haiku-4-5

Sensitivity

Regulated85%llm-generatedllm:claude-haiku-4-5

Information Class

unclassified

Variants

plural
External Information System or Components
possessive
External Information System or Component's
pluralpossessive
External Information System or Components'

Framework definitions

NISTIR 7298: Glossary of Key Information Security Terms, Revision 21 senseview framework →
§1
An information system or component of an information system that is outside of the authorization boundary established by the organization and for which the organization typically has no direct control over the application of required security controls or the assessment of security control effectiveness.
CNSSI-4009 (Glossary of Information Assurance Terms)1 senseview framework →
§1
An information system or component of an information system that is outside of the authorization boundary established by the organization and for which the organization typically has no direct control over the application of required security controls or the assessment of security control effectiveness.
NIST SP 800-531 senseview framework →
§1
An information system or component of an information system that is outside of the authorization boundary established by the organization and for which the organization typically has no direct control over the application of required security controls or the assessment of security control effectiveness.
NIST SP 800-371 senseview framework →
§1
An information system or component of an information system that is outside of the authorization boundary established by the organization and for which the organization typically has no direct control over the application of required security controls or the assessment of security control effectiveness.

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.