STIGhub
STIGs
RMF Controls
Compare
← All Controls
SA-9
System and Services Acquisition
Rev 5
External System Services
CCI Identifiers (15)
CCI-000669
Require that providers of external system services comply with organizational security requirements.
CCI-000670
The organization requires that providers of external information system services employ organization-defined security controls in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance.
CCI-000671
The organization defines government oversight with regard to external information system services.
CCI-000672
The organization documents government oversight with regard to external information system services.
CCI-000673
The organization defines user roles and responsibilities with regard to external information system services.
CCI-000674
The organization documents user roles and responsibilities with regard to external information system services.
CCI-000675
The organization monitors security control compliance by external service providers.
CCI-003137
The organization defines security controls that providers of external information system services employ in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance.
CCI-003138
Employ organization-defined processes, methods, and techniques to monitor control compliance by external service providers on an ongoing basis.
CCI-003139
Defines processes, methods, and techniques to employ to monitor control compliance by external service providers on an ongoing basis.
CCI-004782
Require that providers of external system services comply with organizational privacy requirements.
CCI-004783
Require that providers of external system services employ organization-defined controls.
CCI-004784
Defines the controls for complying with organizational security and privacy requirements.
CCI-004785
Define and document organizational oversight with regard to external system services.
CCI-004786
Define and document user roles and responsibilities with regard to external system services.
Linked STIG Checks (0)
No STIG checks reference this control.