|
controlSA-9

External System Services (SA-9)

Require that providers of external system services comply with organizational security and privacy requirements and employ the following controls: [organization-defined]; Define and document organizational oversight and user roles and responsibilities with regard to external system services; and Employ the following processes, methods, and techniques to monitor control compliance by external service providers on an ongoing basis: [organization-defined].

Security Baselines

LOWMODERATEHIGH
acquisitionsdlcservicessupply-chain

Why These Connect

Maps To24

These are equivalent or closely aligned requirements in other frameworks.

Baselined In3

This control is included in the linked security baseline (LOW, MODERATE, or HIGH).

Supports37

These related controls work together — a change to one may affect the others.

Mitigates2

This control helps defend against or reduce the risk of the linked threat technique.

Enhances8

These enhancements add specific capabilities or refinements to the base control.

Threat Coverage(2 ATT&CK techniques)

Cross-Framework Mappings(24)

GV.SC-04GV.SC-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.SC-05GV.SC-05Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.SC-06GV.SC-06Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.SC-07GV.SC-07Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.SC-08GV.SC-08Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.SC-09GV.SC-09Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.SC-10GV.SC-10Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.AM-02ID.AM-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.AM-04ID.AM-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.OC-05GV.OC-05Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
DE.CM-06DE.CM-06Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20227 mappingsFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
HIPAAHIPAA Security Rule7 mappingsFinal
NIST OLIR informative reference — HIPAA Security Rule to SP 800-53 Rev 5
GV.SC-04GV.SC-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.SC-05GV.SC-05Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.SC-06GV.SC-06Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.SC-07GV.SC-07Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.SC-08GV.SC-08Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.SC-09GV.SC-09Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.SC-10GV.SC-10Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.AM-02ID.AM-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.AM-04ID.AM-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.OC-05GV.OC-05Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
DE.CM-06DE.CM-06Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5

Organization-Defined Parameters(2)

Assignmentorganization-defined controls
Assignmentorganization-defined processes, methods, and techniques

Control Enhancements(8)