id: "SA-09(05)" title: "Processing, Storage, and Service Location" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-09.05" priority: "P1" implementation_level: "organization" parent: "SA-09" enhancement: True


Statement

Restrict the location of {{ insert: param, sa-09.05_odp.01 }} to {{ insert: param, sa-09.05_odp.02 }} based on {{ insert: param, sa-09.05_odp.03 }}.

Guidance

The location of information processing, information and data storage, or system services can have a direct impact on the ability of organizations to successfully execute their mission and business functions. The impact occurs when external providers control the location of processing, storage, or services. The criteria that external providers use for the selection of processing, storage, or service locations may be different from the criteria that organizations use. For example, organizations may desire that data or information storage locations be restricted to certain locations to help facilitate incident response activities in case of information security incidents or breaches. Incident response activities, including forensic analyses and after-the-fact investigations, may be adversely affected by the governing laws, policies, or protocols in the locations where processing and storage occur and/or the locations from which system services emanate.

Assessment Objective

based on {{ insert: param, sa-09.05_odp.03 }}, {{ insert: param, sa-09.05_odp.01 }} is/are restricted to {{ insert: param, sa-09.05_odp.02 }}.

System and services acquisition policy

procedures addressing external system services

acquisition contracts for the system, system component, or system service

solicitation documentation

acquisition documentation

service level agreements

restricted locations for information processing

information/data and/or system services

information processing, information/data, and/or system services to be maintained in restricted locations

organizational security requirements or conditions for external providers

system security plan

supply chain risk management plan

other relevant documents or records

Organizational personnel with system and service acquisition responsibilities

organizational personnel with information security responsibilities

external providers of system services

organizational personnel with supply chain risk management responsibilities

Organizational processes for defining the requirements to restrict locations of information processing, information/data, or information services

organizational processes for ensuring the location is restricted in accordance with requirements or conditions