FedRAMP Controls / SA

SA-9 External System Services

Family SA
Baselines moderate
Mapped KSIs 2

Control statement

a. Require that providers of external system services comply with organizational security and privacy requirements and employ the following controls: {{ insert: param, sa-09_odp.01 }};
    b. Define and document organizational oversight and user roles and responsibilities with regard to external system services; and
    c. Employ the following processes, methods, and techniques to monitor control compliance by external service providers on an ongoing basis: {{ insert: param, sa-09_odp.02 }}.

Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is preserved in the catalog database.

Covered by these Key Security Indicators

KSITitleCategory
KSI-TPR-03Supply Chain Risk Management
_Persistently_ identify, review, and mitigate potential supply chain risks.
Third-Party Information Resources
KSI-TPR-04Supply Chain Risk Monitoring
Automatically monitor third party software _information resources_ for upstream vulnerabilities using mechanisms that may include contractual notification requirements or active monitoring services.
Third-Party Information Resources