NIST SP 800-53 Rev. 5
SA-9(1)
System and Services Acquisition
enhancement

Risk Assessments and Organizational Approvals

Parent: SA-9

Description

a. Conduct an organizational assessment of risk prior to the acquisition or outsourcing of information security services; and b. Verify that the acquisition or outsourcing of dedicated information security services is approved by [organization-defined parameter].

Mapped SPARTA techniques

67 techniques

Cite as SafeMode Space, nist-80053-rev5 SA-9(1).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.