NIST 800-53 SA-09 Mappings

External system services are provided by an external provider, and the organization has no direct control over the implementation of the required controls or the assessment of control effectiveness. Organizations establish relationships with external service providers in a variety of ways, including through business partnerships, contracts, interagency agreements, lines of business arrangements, licensing agreements, joint ventures, and supply chain exchanges. The responsibility for managing risks from the use of external system services remains with authorizing officials. For services external to organizations, a chain of trust requires that organizations establish and retain a certain level of confidence that each provider in the consumer-provider relationship provides adequate protection for the services rendered. The extent and nature of this chain of trust vary based on relationships between organizations and the external providers. Organizations document the basis for the trust relationships so that the relationships can be monitored. External system services documentation includes government, service providers, end user security roles and responsibilities, and service-level agreements. Service-level agreements define the expectations of performance for implemented controls, describe measurable outcomes, and identify remedies and response requirements for identified instances of noncompliance.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name
SA-09 External System Services Protects T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
SA-09 External System Services Protects T1072 Software Deployment Tools
SA-09 External System Services Protects T1041 Exfiltration Over C2 Channel
SA-09 External System Services Protects T1567 Exfiltration Over Web Service
SA-09 External System Services Protects T1048 Exfiltration Over Alternative Protocol
SA-09 External System Services Protects T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol