AC-20 Use of External Systems
Initial Implementation: 10/1/2022
Last Review: 10/7/2025
        Last Review: 10/7/2025
Statement
West Texas A&M University establishes terms and conditions, consistent with any trust relationships established with other organizations owning, operating, and/or maintaining external information systems, allowing authorized individuals to: (1) access the information system from external information systems; and (2) process, store, or transmit organization-controlled information using external information systems. Users must receive authorization before using an externally-managed information system.
Applicability
This Control applies to all West Texas A&M network information resources. The intended audience for this Control includes all information resource owners, custodians, and users of information resources.
Implementation
- Any third party system shall follow control SC-4 Acquisition Process prior to implementation.
- All connections between WTAMU information systems and external systems must be approved and documented.
- All requests for external connections must be made through the service request system and/or project management request and systems.
- All third party connection requests must have approval from the WTAMU CIO/IRM.
- Any third party system authorized to access, transmit, use or store data for WTAMU shall have a valid contract on file. All contracts shall include a provision to meet security controls as defined by WTAMU, proportionate to the risk.
- Vendors should provide evidience to WTAMU of compliance with security controls upon request or at time of renewal.
 
		 
  
  
  
 