id: "SA-09(01)" title: "Risk Assessments and Organizational Approvals" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-09.01" priority: "P1" implementation_level: "organization" parent: "SA-09" enhancement: True
Conduct an organizational assessment of risk prior to the acquisition or outsourcing of information security services; and
Verify that the acquisition or outsourcing of dedicated information security services is approved by {{ insert: param, sa-09.01_odp }}.
Guidance
Information security services include the operation of security devices, such as firewalls or key management services as well as incident monitoring, analysis, and response. Risks assessed can include system, mission or business, security, privacy, or supply chain risks.
Assessment Objective: an organizational assessment of risk is conducted prior to the acquisition or outsourcing of information security services;
Assessment Objective: {{ insert: param, sa-09.01_odp }} approve the acquisition or outsourcing of dedicated information security services.
System and services acquisition policy
supply chain risk management policy and procedures
procedures addressing external system services
acquisition documentation
acquisition contracts for the system, system component, or system service
risk assessment reports
approval records for the acquisition or outsourcing of dedicated security services
system security plan
supply chain risk management plan
other relevant documents or records
Organizational personnel with system and service acquisition responsibilities
organizational personnel with system security responsibilities
external providers of system services
organizational personnel with information security responsibilities
organizational personnel with supply chain risk management responsibilities
Organizational processes for conducting a risk assessment prior to acquiring or outsourcing dedicated security services
organizational processes for approving the outsourcing of dedicated security services
mechanisms supporting and/or implementing risk assessment
mechanisms supporting and/or implementing approval processes