SA-9 - External System Services

a. Require that providers of external system services comply with organizational security and privacy requirements and employ the following controls: [Assignment: organization-defined controls]; b. Define and document organizational oversight and user roles and responsibilities with regard to external system services; and c. Employ the following processes, methods, and techniques to monitor control compliance by external service providers on an ongoing basis: [Assignment: organization-defined processes, methods, and techniques].


ID: SA-9
Enhancements:  1 | 2 | 3 | 4 | 5 | 6 | 7 | 8

Space Segment Guidance

For external service providers (e.g., commercial ground networks, relays, hosted payload operators), contracts should clarify security responsibilities, station/operator vetting, key custody and revocation, audit evidence exchange, incident coordination, and schedule adherence under AOS/LOS realities. Consider pre-onboarding evidence (facility/STA certification, RF configuration discipline, time-sync practices, staff vetting), ongoing compliance monitoring (periodic attestations, telemetry/audit samples), service-level expectations tied to pass windows, and rights to test handovers in a twin/flatsat before reliance during flight.