External System Services
✓ LOW ✓ MODERATE ✓ HIGHRequirements NIST SOURCE
Requirement Context
This element is part of SA-9 — External System Services. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of SA-9 — External System Services. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of SA-9 — External System Services. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Discussion (NIST Supplemental Guidance)
External system services are provided by an external provider, and the organization has no direct control over the implementation of the required controls or the assessment of control effectiveness. Organizations establish relationships with external service providers in a variety of ways, including through business partnerships, contracts, interagency agreements, lines of business arrangements, licensing agreements, joint ventures, and supply chain exchanges. The responsibility for managing risks from the use of external system services remains with authorizing officials. For services external to organizations, a chain of trust requires that organizations establish and retain a certain level of confidence that each provider in the consumer-provider relationship provides adequate protection for the services rendered. The extent and nature of this chain of trust vary based on relationships between organizations and the external providers. Organizations document the basis for the trust relationships so that the relationships can be monitored. External system services documentation includes government, service providers, end user security roles and responsibilities, and service-level agreements. Service-level agreements define the expectations of performance for implemented controls, describe measurable outcomes, and identify remedies and response requirements for identified instances of noncompliance.
Enhancements NIST SOURCE
SA-9(1) Risk Assessments and Organizational Approvals LOW MODERATE HIGH
- (a) Conduct an organizational assessment of risk prior to the acquisition or outsourcing of information security services; and
- (b) Verify that the acquisition or outsourcing of dedicated information security services is approved by [personnel or roles].
Discussion
Information security services include the operation of security devices, such as firewalls or key management services as well as incident monitoring, analysis, and response. Risks assessed can include system, mission or business, security, privacy, or supply chain risks.
SA-9(2) Identification of Functions, Ports, Protocols, and Services LOW ✓ MODERATE ✓ HIGH
Require providers of the following external system services to identify the functions, ports, protocols, and other services required for the use of such services: [external system services].
Discussion
Information from external service providers regarding the specific functions, ports, protocols, and services used in the provision of such services can be useful when the need arises to understand the trade-offs involved in restricting certain functions and services or blocking certain ports and protocols.
SA-9(3) Establish and Maintain Trust Relationship with Providers LOW MODERATE HIGH
Establish, document, and maintain trust relationships with external service providers based on the following requirements, properties, factors, or conditions: [organization-defined security and privacy requirements, properties, factors, or conditions defining acceptable trust relationships].
Discussion
Trust relationships between organizations and external service providers reflect the degree of confidence that the risk from using external services is at an acceptable level. Trust relationships can help organizations gain increased levels of confidence that service providers are providing adequate protection for the services rendered and can also be useful when conducting incident response or when planning for upgrades or obsolescence. Trust relationships can be complicated due to the potentially large number of entities participating in the consumer-provider interactions, subordinate relationships and levels of trust, and types of interactions between the parties. In some cases, the degree of trust is based on the level of control that organizations can exert on external service providers regarding the controls necessary for the protection of the service, information, or individual privacy and the evidence brought forth as to the effectiveness of the implemented controls. The level of control is established by the terms and conditions of the contracts or service-level agreements.
SA-9(4) Consistent Interests of Consumers and Providers LOW MODERATE HIGH
Take the following actions to verify that the interests of [external service providers] are consistent with and reflect organizational interests: [actions].
Discussion
As organizations increasingly use external service providers, it is possible that the interests of the service providers may diverge from organizational interests. In such situations, simply having the required technical, management, or operational controls in place may not be sufficient if the providers that implement and manage those controls are not operating in a manner consistent with the interests of the consuming organizations. Actions that organizations take to address such concerns include requiring background checks for selected service provider personnel; examining ownership records; employing only trustworthy service providers, such as providers with which organizations have had successful trust relationships; and conducting routine, periodic, unscheduled visits to service provider facilities.
SA-9(5) Processing, Storage, and Service Location LOW MODERATE HIGH
Restrict the location of [one of: information processing; information or data; system services] to [locations] based on [requirements].
Discussion
The location of information processing, information and data storage, or system services can have a direct impact on the ability of organizations to successfully execute their mission and business functions. The impact occurs when external providers control the location of processing, storage, or services. The criteria that external providers use for the selection of processing, storage, or service locations may be different from the criteria that organizations use. For example, organizations may desire that data or information storage locations be restricted to certain locations to help facilitate incident response activities in case of information security incidents or breaches. Incident response activities, including forensic analyses and after-the-fact investigations, may be adversely affected by the governing laws, policies, or protocols in the locations where processing and storage occur and/or the locations from which system services emanate.
SA-9(6) Organization-controlled Cryptographic Keys LOW MODERATE HIGH
Maintain exclusive control of cryptographic keys for encrypted material stored or transmitted through an external system.
Discussion
Maintaining exclusive control of cryptographic keys in an external system prevents decryption of organizational data by external system staff. Organizational control of cryptographic keys can be implemented by encrypting and decrypting data inside the organization as data is sent to and received from the external system or by employing a component that permits encryption and decryption functions to be local to the external system but allows exclusive organizational access to the encryption keys.
SA-9(7) Organization-controlled Integrity Checking LOW MODERATE HIGH
Provide the capability to check the integrity of information while it resides in the external system.
Discussion
Storage of organizational information in an external system could limit visibility into the security status of its data. The ability of the organization to verify and validate the integrity of its stored data without transferring it out of the external system provides such visibility.
SA-9(8) Processing and Storage Location — U.S. Jurisdiction LOW MODERATE HIGH
Restrict the geographic location of information processing and data storage to facilities located within in the legal jurisdictional boundary of the United States.
Discussion
The geographic location of information processing and data storage can have a direct impact on the ability of organizations to successfully execute their mission and business functions. A compromise or breach of high impact information and systems can have severe or catastrophic adverse impacts on organizational assets and operations, individuals, other organizations, and the Nation. Restricting the processing and storage of high-impact information to facilities within the legal jurisdictional boundary of the United States provides greater control over such processing and storage.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for SA-9 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- controls to be employed by external system service providers are defined;
- processes, methods, and techniques employed to monitor control compliance by external service providers are defined;
- providers of external system services comply with organizational security requirements;
- providers of external system services comply with organizational privacy requirements;
- providers of external system services employ <SA-09_ODP[01] controls>;
- organizational oversight with regard to external system services are defined and documented;
- user roles and responsibilities with regard to external system services are defined and documented;
- <SA-09_ODP[02] processes, methods, and techniques> are employed to monitor control compliance by external service providers on an ongoing basis.
Examine
[SELECT FROM: System and services acquisition policy; system and services acquisition procedures; procedures addressing methods and techniques for monitoring control compliance by external service providers of system services; acquisition documentation; contracts; service level agreements; interagency agreements; licensing agreements; list of organizational security and privacy requirements for external provider services; control assessment results or reports from external providers of system services; system security plan; privacy plan; supply chain risk management plan; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with acquisition responsibilities; external providers of system services; organizational personnel with information security and privacy responsibilities; organizational personnel with supply chain risk management responsibilities].
Test
[SELECT FROM: Organizational processes for monitoring security and privacy control compliance by external service providers on an ongoing basis; mechanisms for monitoring security and privacy control compliance by external service providers on an ongoing basis].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for SA-9. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- System and services acquisition policy
- system security plan
- privacy plan
- supply chain risk management plan
Testing
- Organizational processes for monitoring security and privacy control compliance by external service providers on an ongoing basis
- mechanisms for monitoring security and privacy control compliance by external service providers on an ongoing basis
Other Records
- system and services acquisition procedures
- procedures addressing methods and techniques for monitoring control compliance by external service providers of system services
- acquisition documentation
- contracts
- service level agreements
- interagency agreements
- licensing agreements
- list of organizational security and privacy requirements for external provider services
- control assessment results or reports from external providers of system services
- other relevant documents or records