id: "SA-09(04)" title: "Consistent Interests of Consumers and Providers" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-09.04" priority: "P1" implementation_level: "organization" parent: "SA-09" enhancement: True


Statement

Take the following actions to verify that the interests of {{ insert: param, sa-09.04_odp.01 }} are consistent with and reflect organizational interests: {{ insert: param, sa-09.04_odp.02 }}.

Guidance

As organizations increasingly use external service providers, it is possible that the interests of the service providers may diverge from organizational interests. In such situations, simply having the required technical, management, or operational controls in place may not be sufficient if the providers that implement and manage those controls are not operating in a manner consistent with the interests of the consuming organizations. Actions that organizations take to address such concerns include requiring background checks for selected service provider personnel; examining ownership records; employing only trustworthy service providers, such as providers with which organizations have had successful trust relationships; and conducting routine, periodic, unscheduled visits to service provider facilities.

Assessment Objective

{{ insert: param, sa-09.04_odp.02 }} are taken to verify that the interests of {{ insert: param, sa-09.04_odp.01 }} are consistent with and reflect organizational interests.

System and services acquisition policy

procedures addressing external system services

acquisition contracts for the system, system component, or system service

solicitation documentation

acquisition documentation

service level agreements

organizational security requirements/safeguards for external service providers

personnel security policies for external service providers

assessments performed on external service providers

system security plan

supply chain risk management plan

other relevant documents or records

Organizational personnel with system and service acquisition responsibilities

organizational personnel with information security responsibilities

external providers of system services

organizational personnel with supply chain risk management responsibilities

Organizational processes for defining and employing safeguards to ensure consistent interests with external service providers

mechanisms supporting and/or implementing safeguards to ensure consistent interests with external service providers