id: "SA-09(07)" title: "Organization-controlled Integrity Checking" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-09.07" priority: "P1" implementation_level: "organization" parent: "SA-09" enhancement: True


Statement

Provide the capability to check the integrity of information while it resides in the external system.

Guidance

Storage of organizational information in an external system could limit visibility into the security status of its data. The ability of the organization to verify and validate the integrity of its stored data without transferring it out of the external system provides such visibility.

Assessment Objective

the capability is provided to check the integrity of information while it resides in the external system.

System and services acquisition policy

procedures addressing external system services

acquisition contracts for the system, system component, or system service

solicitation documentation

acquisition documentation

service level agreements

procedures addressing organization-controlled integrity checking

information/data and/or system services

organizational security requirements or conditions for external providers

system security plan

supply chain risk management plan

other relevant documents or records

Organizational personnel with system and service acquisition responsibilities

organizational personnel with information security responsibilities

organization personnel with integrity checking responsibilities

external providers of system services

organizational personnel with supply chain risk management responsibilities

Organizational processes for integrity checking

mechanisms for supporting and implementing integrity checking of information in external systems