id: "SA-09(07)" title: "Organization-controlled Integrity Checking" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-09.07" priority: "P1" implementation_level: "organization" parent: "SA-09" enhancement: True
Statement
Provide the capability to check the integrity of information while it resides in the external system.
Guidance
Storage of organizational information in an external system could limit visibility into the security status of its data. The ability of the organization to verify and validate the integrity of its stored data without transferring it out of the external system provides such visibility.
Assessment Objective
the capability is provided to check the integrity of information while it resides in the external system.
System and services acquisition policy
procedures addressing external system services
acquisition contracts for the system, system component, or system service
solicitation documentation
acquisition documentation
service level agreements
procedures addressing organization-controlled integrity checking
information/data and/or system services
organizational security requirements or conditions for external providers
system security plan
supply chain risk management plan
other relevant documents or records
Organizational personnel with system and service acquisition responsibilities
organizational personnel with information security responsibilities
organization personnel with integrity checking responsibilities
external providers of system services
organizational personnel with supply chain risk management responsibilities
Organizational processes for integrity checking
mechanisms for supporting and implementing integrity checking of information in external systems