id: "SA-09(05)" title: "Processing, Storage, and Service Location" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-09.05" priority: "P1" implementation_level: "organization" parent: "SA-09" enhancement: True
Statement
Restrict the location of {{ insert: param, sa-09.05_odp.01 }} to {{ insert: param, sa-09.05_odp.02 }} based on {{ insert: param, sa-09.05_odp.03 }}.
Guidance
The location of information processing, information and data storage, or system services can have a direct impact on the ability of organizations to successfully execute their mission and business functions. The impact occurs when external providers control the location of processing, storage, or services. The criteria that external providers use for the selection of processing, storage, or service locations may be different from the criteria that organizations use. For example, organizations may desire that data or information storage locations be restricted to certain locations to help facilitate incident response activities in case of information security incidents or breaches. Incident response activities, including forensic analyses and after-the-fact investigations, may be adversely affected by the governing laws, policies, or protocols in the locations where processing and storage occur and/or the locations from which system services emanate.
Assessment Objective
based on {{ insert: param, sa-09.05_odp.03 }}, {{ insert: param, sa-09.05_odp.01 }} is/are restricted to {{ insert: param, sa-09.05_odp.02 }}.
System and services acquisition policy
procedures addressing external system services
acquisition contracts for the system, system component, or system service
solicitation documentation
acquisition documentation
service level agreements
restricted locations for information processing
information/data and/or system services
information processing, information/data, and/or system services to be maintained in restricted locations
organizational security requirements or conditions for external providers
system security plan
supply chain risk management plan
other relevant documents or records
Organizational personnel with system and service acquisition responsibilities
organizational personnel with information security responsibilities
external providers of system services
organizational personnel with supply chain risk management responsibilities
Organizational processes for defining the requirements to restrict locations of information processing, information/data, or information services
organizational processes for ensuring the location is restricted in accordance with requirements or conditions