SA-9(1): Risk Assessments / Organizational Approvals

Baselines:

(Not part of any baseline)

Next Version:

Control Statement

The organization:

  1. Conducts an organizational assessment of risk prior to the acquisition or outsourcing of dedicated information security services; and
  2. Ensures that the acquisition or outsourcing of dedicated information security services is approved by [Assignment: organization-defined personnel or roles].

Supplemental Guidance

Dedicated information security services include, for example, incident monitoring, analysis and response, operation of information security-related devices such as firewalls, or key management services.