Show/Hide Toolbars

ABCI Consultants

Guidance for NIST 800-171 Assessment & Compliance

Navigation: SA-FAMILY: SYSTEM AND SERVICES ACQUISITION

SA-9(2) EXTERNAL INFORMATION SYSTEM SERVICES  |  IDENTIFICATION OF FUNCTIONS / PORTS / PROTOCOLS / SERVICES

Scroll Prev Top Next More

Applicable

(Y)es / (N)o

(C)onfidentiality

(I)ntegrity

(A)vailability

RPN

(C+I+A)

(S)atisfactory

L1

M2

H3

L1

M2

H3

L1

M2

H3

(O)ther than satisfactory +##

 

 

 

 

 

 

 

 

 

 

 

 

###

sa-9(2)

external information system services  | identification of functions / ports / protocols / services

 

assessment objective:

Determine if the organization:

sa-9(2)[1]

defines external information system services for which providers of such services are to identify the functions, ports, protocols, and other services required for the use of such services;

sa-9(2)[2]

requires providers of organization-defined external information system services to identify:

sa-9(2)[2][a]

the functions required for the use of such services;

sa-9(2)[2][b]

the ports required for the use of such services;

sa-9(2)[2][c]

the protocols required for the use of such services; and

sa-9(2)[2][d]

the other services required for the use of such services.

potential assessment methods and objects:

Examine: [select from: System and services acquisition policy; procedures addressing external information system services; acquisition contracts for the information system, system component, or information system service; acquisition documentation; solicitation documentation, service-level agreements; organizational security requirements and security specifications for external service providers; list of required functions, ports, protocols, and other services; other relevant documents or records].

Interview: [select from: Organizational personnel with system and services acquisition responsibilities; organizational personnel with information security responsibilities; system/network administrators; external providers of information system services].

Hosted by ABCI Consultants for Information Security Management Systems | Implementations, Training and Assessments for Compliance | (800) 644-2056