Skip to main content

๐Ÿ’ผ SA-9 (1) RISK ASSESSMENTS | ORGANIZATIONAL APPROVALS

Descriptionโ€‹

The organization: SA-9 (1)(a) Conducts an organizational assessment of risk prior to the acquisition or outsourcing of dedicated information security services; and SA-9 (1)(b) Ensures that the acquisition or outsourcing of dedicated information security services is approved by [Assignment: organization-defined personnel or roles].

Similarโ€‹

  • Internal
    • ID: dec-c-bb18f135

Sub Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlags