id: "SA-09(01)" title: "Risk Assessments and Organizational Approvals" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-09.01" priority: "P1" implementation_level: "organization" parent: "SA-09" enhancement: True


Conduct an organizational assessment of risk prior to the acquisition or outsourcing of information security services; and

Verify that the acquisition or outsourcing of dedicated information security services is approved by {{ insert: param, sa-09.01_odp }}.

Guidance

Information security services include the operation of security devices, such as firewalls or key management services as well as incident monitoring, analysis, and response. Risks assessed can include system, mission or business, security, privacy, or supply chain risks.

Assessment Objective: an organizational assessment of risk is conducted prior to the acquisition or outsourcing of information security services;

Assessment Objective: {{ insert: param, sa-09.01_odp }} approve the acquisition or outsourcing of dedicated information security services.

System and services acquisition policy

supply chain risk management policy and procedures

procedures addressing external system services

acquisition documentation

acquisition contracts for the system, system component, or system service

risk assessment reports

approval records for the acquisition or outsourcing of dedicated security services

system security plan

supply chain risk management plan

other relevant documents or records

Organizational personnel with system and service acquisition responsibilities

organizational personnel with system security responsibilities

external providers of system services

organizational personnel with information security responsibilities

organizational personnel with supply chain risk management responsibilities

Organizational processes for conducting a risk assessment prior to acquiring or outsourcing dedicated security services

organizational processes for approving the outsourcing of dedicated security services

mechanisms supporting and/or implementing risk assessment

mechanisms supporting and/or implementing approval processes