SA-9(1) - External System Services | Risk Assessments and Organizational Approvals

(a) Conduct an organizational assessment of risk prior to the acquisition or outsourcing of information security services; and (b) Verify that the acquisition or outsourcing of dedicated information security services is approved by [Assignment: organization-defined personnel or roles].


ID: SA-9(1)
Enhancement of : SA-9