Skip to main content

πŸ’Ό SA-9 External System Services (L)(M)(H)

  • Contextual name: πŸ’Ό SA-9 External System Services (L)(M)(H)
  • ID: /frameworks/fedramp-high-security-controls/sa/09
  • Located in: πŸ’Ό System and Services Acquisition

Description​

a. Require that providers of external system services comply with organizational security and privacy requirements and employ the following controls: [FedRAMP Assignment: Appropriate FedRAMP Security Controls Baseline(s) if Federal information is processed or stored within the external system];

b. Define and document organizational oversight and user roles and responsibilities with regard to external system services; and

c. Employ the following processes, methods, and techniques to monitor control compliance by external service providers on an ongoing basis: [FedRAMP Assignment: Federal/FedRAMP Continuous Monitoring requirements must be met for external systems where Federal information is processed or stored].

Similar​

  • Sections
    • /frameworks/nist-sp-800-53-r5/sa/09
  • Internal
    • ID: dec-c-fc6e80de

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό SA-9 External System Services811

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό FedRAMP Low Security Controls β†’ πŸ’Ό SA-9 External System Services (L)(M)(H)
πŸ’Ό FedRAMP Moderate Security Controls β†’ πŸ’Ό SA-9 External System Services (L)(M)(H)31

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό SA-9(1) Risk Assessments and Organizational Approvals (M)(H)
πŸ’Ό SA-9(2) Identification of Functions, Ports, Protocols, and Services (M)(H)
πŸ’Ό SA-9(5) Processing, Storage, and Service Location (M)(H)1