# SA-9 — External System Services

- **Control ID:** SA-9
- **Family:** [SA](/md/families/SA.md)
- **Baselines:** low, moderate, high
- **Enhancement of:** No content available.

## Description

Require that providers of external system services comply with organizational security and privacy requirements and employ the following controls: \[assignment\]; Define and document organizational oversight and user roles and responsibilities with regard to external system services; and Employ the following processes, methods, and techniques to monitor control compliance by external service providers on an ongoing basis: \[assignment\].

## Discussion

External system services are provided by an external provider, and the organization has no direct control over the implementation of the required controls or the assessment of control effectiveness. Organizations establish relationships with external service providers in a variety of ways, including through business partnerships, contracts, interagency agreements, lines of business arrangements, licensing agreements, joint ventures, and supply chain exchanges. The responsibility for managing risks from the use of external system services remains with authorizing officials. For services external to organizations, a chain of trust requires that organizations establish and retain a certain level of confidence that each provider in the consumer-provider relationship provides adequate protection for the services rendered. The extent and nature of this chain of trust vary based on relationships between organizations and the external providers. Organizations document the basis for the trust relationships so that the relationships can be monitored. External system services documentation includes government, service providers, end user security roles and responsibilities, and service-level agreements. Service-level agreements define the expectations of performance for implemented controls, describe measurable outcomes, and identify remedies and response requirements for identified instances of noncompliance.

## Implementation guidance

No content available.

## CSF 2.0 subcategories

- [DE.CM-06](/md/csf/DE.CM-06.md) — External service provider activities and services are monitored to find potentially adverse events
- [GV.OC-05](/md/csf/GV.OC-05.md) — Outcomes, capabilities, and services that the organization depends on are understood and communicated
- [GV.SC-04](/md/csf/GV.SC-04.md) — Suppliers are known and prioritized by criticality
- [GV.SC-05](/md/csf/GV.SC-05.md) — Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
- [GV.SC-06](/md/csf/GV.SC-06.md) — Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
- [GV.SC-07](/md/csf/GV.SC-07.md) — The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
- [GV.SC-08](/md/csf/GV.SC-08.md) — Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
- [GV.SC-09](/md/csf/GV.SC-09.md) — Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
- [GV.SC-10](/md/csf/GV.SC-10.md) — Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement
- [ID.AM-02](/md/csf/ID.AM-02.md) — Inventories of software, services, and systems managed by the organization are maintained
- [ID.AM-04](/md/csf/ID.AM-04.md) — Inventories of services provided by suppliers are maintained

## Related controls

- [AC-20](/md/controls/AC-20.md)
- [CA-3](/md/controls/CA-3.md)
- [CP-2](/md/controls/CP-2.md)
- [IR-4](/md/controls/IR-4.md)
- [IR-7](/md/controls/IR-7.md)
- [PL-10](/md/controls/PL-10.md)
- [PL-11](/md/controls/PL-11.md)
- [PS-7](/md/controls/PS-7.md)
- [SA-2](/md/controls/SA-2.md)
- [SA-4](/md/controls/SA-4.md)
- [SR-3](/md/controls/SR-3.md)
- [SR-5](/md/controls/SR-5.md)

---

Derived from official NIST publications (NIST SP 800-53 Rev 5 and NIST CSF 2.0). nistcontrols.com is not affiliated with NIST.
