NIST SP 800-53 Rev. 5
SA-9
System and Services Acquisition

External System Services

Description

a. Require that providers of external system services comply with organizational security and privacy requirements and employ the following controls: [organization-defined parameter]; b. Define and document organizational oversight and user roles and responsibilities with regard to external system services; and c. Employ the following processes, methods, and techniques to monitor control compliance by external service providers on an ongoing basis: [organization-defined parameter].

Mapped SPARTA techniques

106 techniques

Cross-framework references

Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.

Referenced by 11 in NIST Cybersecurity Framework 2.0

Cite as SafeMode Space, nist-80053-rev5 SA-9.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.