home/glossary/external system (or component)

external system (or component)

nounid 163408·updated Aug 30, 2026
verified

A system or component of a system that is outside of the authorization boundary established by the organization and for which the organization typically has no direct control over the application of required security controls or the assessment of security control effectiveness.

MWE

Source

document
NIST Special Publication 800 NIST SP 800-172r3 Enhanced Security Requirements for Protecting Controlled Unclassified Information
publisher
NIST
found in
Appendix B. Glossary
discovery
AuthoritativeImport

Proposed during multiword review of this document in the CKI mapping queue.

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems1 citation · 1 defined by this document · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
3.2.2 ¶ 46

Classifications

Entity Type

System95%llm-generatedllm:claude-haiku-4-5

Sensitivity

Regulated85%llm-generatedllm:claude-haiku-4-5

Information Class

unclassified

Variants

No variants recorded
This term has no surface-form variants in the lexicon yet, so it tags only its canonical form.

Framework definitions

NIST SP 800-172r31 senseview framework →
§1 · glossary
A system or component of a system that is outside of the authorization boundary established by the organization and for which the organization typically has no direct control over the application of required security controls or the assessment of security control effectiveness.
Attribution from the CKI glossary mapping stage (glossary)
NIST SP 800-171r31 senseview framework →
§1 · glossary
A system or component of a system that is outside of the authorization boundary established by the organization and for which the organization typically has no direct control over the application of required security controls or the assessment of security control effectiveness.
Attribution from the CKI glossary mapping stage (glossary)
Legacy lexicon import1 senseview framework →
§1 · legacy_primary
A system or component of a system that is outside of the authorization boundary established by the organization and for which the organization typically has no direct control over the application of required security controls or the assessment of security control effectiveness.
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.