CCI-000672
CCI-000672 Definition
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed must establish in the official documentation governing the provision of the external IT services (e.g. contract, MOU, MOA, SLA, etc) the government oversight to be conducted on external information system services and service provider.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the official documentation governing the provision of the external IT services (e.g. contract, MOU, MOA, SLA, etc) to confirm the organization has clearly established the government oversight to be conducted on external information system services and service providers.
Compelling Evidence
1.) System security plan (SSP) must define how government oversight is implemented with regards to external information services (includes contracts, MOUs, MOAs, SLAs).