# SA-09 External System Services

NIST SP 800-53 control. Family: SA System and Services Acquisition. Function: preventative. Baselines: low, moderate, high, privacy. Mapping licence: CC BY-SA 4.0.

Statement: a. Require that providers of external system services comply with organizational security and privacy requirements and employ the following controls: [Assignment: organization-defined controls]; b. Define and document organizational oversight and user roles and responsibilities with regard to external system services; and c. Employ the following processes, methods, and techniques to monitor control compliance by external service providers on an ongoing basis: [Assignment: organization-defined processes, methods, and techniques].
Guidance: External system services are provided by an external provider, and the organization has no direct control over the implementation of the required controls or the assessment of control effectiveness. Organizations establish relationships with external service providers in a variety of ways, including through business partnerships, contracts, interagency agreements, lines of business arrangements, licensing agreements, joint ventures, and supply chain exchanges. The responsibility for managing risks from the use of external system services remains with authorizing officials. For services external to organizations, a chain of trust requires that organizations establish and retain a certain level of confidence that each provider in the consumer-provider relationship provides adequate protection for the services rendered. The extent and nature of this chain of trust vary based on relationships between organizations and the external providers. Organizations document the basis for the trust relationships so that the relationships can be monitored. External system services documentation includes government, service providers, end user security roles and responsibilities, and service-level agreements. Service-level agreements define the expectations of performance for implemented controls, describe measurable outcomes, and identify remedies and response requirements for identified instances of noncompliance.

## Enhancements (8)
- SA-09(01) Risk Assessments and Organizational Approvals
- SA-09(02) Identification of Functions, Ports, Protocols, and Services. Baselines: moderate, high
- SA-09(03) Establish and Maintain Trust Relationship with Providers
- SA-09(04) Consistent Interests of Consumers and Providers
- SA-09(05) Processing, Storage, and Service Location
- SA-09(06) Organization-controlled Cryptographic Keys
- SA-09(07) Organization-controlled Integrity Checking
- SA-09(08) Processing and Storage Location — U.S. Jurisdiction
Each enhancement's statement: /api/v1/controls/SA-09?fields=enhancements

## Patterns that use it (17)
- Critical (4): SP-011 Cloud Computing Pattern; SP-027 Secure LLM Usage; SP-042 Third Party Risk Management; SP-047 Secure Agentic AI Frameworks
- Important (10): SP-028 Secure DevOps Pipeline Pattern; SP-032 Modern Authentication; SP-034 Cyber Resilience; SP-037 Privileged User Management; SP-038 Vulnerability Management and Patching; SP-044 SaaS Identity Lifecycle Management; SP-046 External Attack Surface Management; SP-049 AI in Security Operations (draft); SP-052 Decentralised Identity & Verifiable Credentials (draft); SP-054 CBDC and Digital Currency Infrastructure (draft)
- Standard (3): SP-017 Secure Network Zone Module; SP-035 Offensive Security Testing; SP-036 Incident Response

## Clauses by framework (74 frameworks)
- iso_27001_2022: A.5.2, A.5.4, A.5.8, A.5.14, A.5.19, A.5.20, A.5.22, A.5.23, A.8.21, A.8.30. OSA's own, not in NIST's crosswalk: A.5.19, A.5.20, A.8.30
- iso_27002_2022: 5.19, 5.20, 5.22, 5.23, 6.6, 8.21, 8.30
- cobit_2019: APO08, APO09, APO10
- pci_dss_v4: 12.8, 12.9
- nist_csf_2: DE.CM-06, GV.OC-05, GV.SC-02, GV.SC-04, GV.SC-05, GV.SC-06, GV.SC-07, GV.SC-08, GV.SC-09, GV.SC-10, ID.AM-02, ID.AM-04. OSA's own, not in NIST's crosswalk: GV.SC-02
- cis_controls_v8: CIS 8.12, CIS 15, CIS 15.1, CIS 15.2, CIS 15.3, CIS 15.4, CIS 15.5, CIS 15.6, CIS 15.7
- soc2_tsc: CC3.3
- iso_42001_2023: A.10.2, A.10.4
- nis2: Art. 21(2)(d)
- apra_cps_234: Para 29-33
- mas_trm: 16
- pra_op_resilience: SS1/21-5.2, SS1/21-5.3, SS1/21-9.1, SS2/21-3.1, SS2/21-5.1, SS2/21-6.1, SS2/21-6.2, SS2/21-7.1, SS2/21-8.1, SS2/21-9.1, SS2/21-10.1, SS2/21-11.1, SS2/21-12.1, SS2/21-13.1, SS2/21-14.1, SS2/21-16.1
- anssi: Hygiene.9, Hygiene.26, Hygiene.42, SecNumCloud.16.1, SecNumCloud.16.2
- osfi_b13: B-13.4.1, B-13.4.2
- finma_circular: IV.F(100), V(101), V(102), V(103), V(104)
- gdpr: Art.28(1), Art.28(3), Art.44, Art.46(1), Art.46(2)
- dora: Art.28(1)(a), Art.28(2), Art.28(5), Art.30(2), Art.30(3)
- bio2: 5.19, 5.20, 5.22, 5.23, 6.6, 8.21, 8.30
- rbi_csf: Annex1.11, ITGRCA.10
- fisc: FISC.O6, FISC.T9
- lgpd_bcb: BCB.Art.11, BCB.Art.11-Supp, BCB.Art.12, BCB.Art.13, BCB.Art.14, BCB.Art.15, BCB.Art.16, BCB.OpenFinance, LGPD.Art.23-26, LGPD.Art.33-36
- hkma_tme1: TME1.3.4, TME1.12.1, TME1.12.2, TME1.12.3, TME1.12.4
- mlps_2: 8.1.9.3, 8.1.9.4, 8.1.9.7, 8.1.10.12, 8.2
- dnb_good_practice: DNB.14.1, DNB.14.2, DNB.16.3
- cra: CRA.I.2i, CRA.Info.8f
- swift_cscf: SWIFT.2.8
- cbb_tm: TM-15
- cbuae: CR-12
- nca_ecc: 4-1, 4-2
- qatar_nia: SD
- sama_csf: 4.1, 4.2, 4.3
- uae_ia: T10
- bog_cisd: CISD-SDLC, CISD-XI, CISD-XII, CISD-XIII, CISD-XVI
- bom_ctrm: 3.9, 3.10
- cbe_csf: CTO-11, OVM-1
- cbn_csf: Part2.4, Part5.1
- popia: s20, s21, s72
- sa_js2: JS2-8.7
- bcbs_239: Principle 14
- bot_cyber: Ch5.1, Ch5.2
- cpmi_pfmi: CG.ID, PFMI.P3, PFMI.P17, PFMI.P22
- eba_ict: 3.2.3
- ecb_croe: CROE.2.2.2, CROE.2.2.3
- ffiec_is: II.C.6, II.C.14, II.C.20
- hipaa_sr: §164.308(b)(1), §164.308(b)(3), §164.314(a)(1), §164.314(a)(2), §164.314(b)(1)
- iosco_cyber: GOV-5, ID-2, PFMI-20, PROT-7
- nydfs_500: 500.10, 500.11
- sebi_cscrf: GV.SC, PR.CS
- nerc_cip: CIP-013-2
- nrc_73_54: RG5.71-C-SR
- ferc_cip: Order 829
- doe_c2m2: THIRD
- api_1164: Sec 12
- awia: AWWA Sec 7
- pci_pts: H
- cbest: CBEST.8
- tiber_eu: TIBER.PROV
- common_criteria: CCRA
- isae_3402: Clause 7, Clause 8
- fca_sysc_13: SYSC 13.9.1, SYSC 13.9.2, SYSC 13.9.3, SYSC 13.9.5
- fda_cyber: TR-3
- hitrust_csf: 05.b
- iso_27799: 14.1, 15.1, 15.2
- lloyds_ms: BP2.2, MS6.1, MS8.8, MS9.3, MS13.1
- naic_ds: 4-personnel, 4D
- nhs_dspt: NDG-10.1, NDG-10.2, NDG-10.3
- solvency_ii: Art.49(1), Art.49(2), Art.49(3), DR.272, DR.274, EIOPA-Cloud-GL3, EIOPA-Cloud-GL11
- csa_ccm_v4: DSP-13, DSP-14, DSP-19, IPY-02, IPY-03, STA-06, STA-09, STA-12, UEM-14
- csa_aicm: DSP-13, DSP-14, DSP-19, DSP-23, IPY-02, IPY-03, MDS-12, STA-06, STA-09, STA-12, STA-16, UEM-14
- mica: Art.66(1), Art.66(3)
- basel_sco60: SCO60.4, SCO60.41, SCO60.53, SCO60.54, SCO60.65, SCO60.83, SCO60.84
- bssc: GSP-07
- sec_custody_digital: SEC-CD-01, SEC-CD-09, SEC-CD-10, SEC-CD-17
- dpdpa: Act.6(6), Act.8(1), Act.8(2), Act.8(5), Act.8(7), Act.16, Rules.6(1)(f), Rules.8(3), Rules.13(4), Rules.15, Rules.Sch1.B.7
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/SA-09
- Clauses only: /api/v1/controls/SA-09?fields=mappings
- Page for people: /controls/sa-09/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
