SA-09(04) Consistent Interests of Consumers and Providers

Take the following actions to verify that the interests of sa-09.04_odp.01 are consistent with and reflect organizational interests: sa-09.04_odp.02.

Parameter ID Definition
sa-09.04_odp.01 external service providers
sa-09.04_odp.02 actions

Baselines

Guidance

As organizations increasingly use external service providers, it is possible that the interests of the service providers may diverge from organizational interests. In such situations, simply having the required technical, management, or operational controls in place may not be sufficient if the providers that implement and manage those controls are not operating in a manner consistent with the interests of the consuming organizations. Actions that organizations take to address such concerns include requiring background checks for selected service provider personnel; examining ownership records; employing only trustworthy service providers, such as providers with which organizations have had successful trust relationships; and conducting routine, periodic, unscheduled visits to service provider facilities.