id: "SA-09(04)" title: "Consistent Interests of Consumers and Providers" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-09.04" priority: "P1" implementation_level: "organization" parent: "SA-09" enhancement: True
Statement
Take the following actions to verify that the interests of {{ insert: param, sa-09.04_odp.01 }} are consistent with and reflect organizational interests: {{ insert: param, sa-09.04_odp.02 }}.
Guidance
As organizations increasingly use external service providers, it is possible that the interests of the service providers may diverge from organizational interests. In such situations, simply having the required technical, management, or operational controls in place may not be sufficient if the providers that implement and manage those controls are not operating in a manner consistent with the interests of the consuming organizations. Actions that organizations take to address such concerns include requiring background checks for selected service provider personnel; examining ownership records; employing only trustworthy service providers, such as providers with which organizations have had successful trust relationships; and conducting routine, periodic, unscheduled visits to service provider facilities.
Assessment Objective
{{ insert: param, sa-09.04_odp.02 }} are taken to verify that the interests of {{ insert: param, sa-09.04_odp.01 }} are consistent with and reflect organizational interests.
System and services acquisition policy
procedures addressing external system services
acquisition contracts for the system, system component, or system service
solicitation documentation
acquisition documentation
service level agreements
organizational security requirements/safeguards for external service providers
personnel security policies for external service providers
assessments performed on external service providers
system security plan
supply chain risk management plan
other relevant documents or records
Organizational personnel with system and service acquisition responsibilities
organizational personnel with information security responsibilities
external providers of system services
organizational personnel with supply chain risk management responsibilities
Organizational processes for defining and employing safeguards to ensure consistent interests with external service providers
mechanisms supporting and/or implementing safeguards to ensure consistent interests with external service providers