Security requirement
- a.Require the providers of external system services used for the processing, storage, or transmission of CUI to comply with the following security requirements: [Organization-defined: security requirements].
- b.Define and document user roles and responsibilities with regard to external system services, including shared responsibilities with external service providers.
- c.Implement processes, methods, and techniques to monitor security requirement compliance by external service providers on an ongoing basis.
Discussion
External system services are provided by external service providers. Organizations establish relationships with external service providers in a variety of ways, including through business partnerships, contracts, interagency agreements, lines of business arrangements, licensing agreements, joint ventures, and supply chain exchanges. The responsibility for managing risks from the use of external system services remains with the organization charged with protecting CUI. Service-level agreements define expectations of performance, describe measurable outcomes, and identify remedies, mitigations, and response requirements for instances of noncompliance. Information from external service providers regarding the specific functions, ports, protocols, and services used in the provision of such services can be useful when there is a need to understand the trade-offs involved in restricting certain functions and services or blocking certain ports and protocols. This requirement is related to 03.01.20.
Tailoring decisions required
Resolve these values through the governing organization’s approved tailoring and risk-management process before declaring the requirement implemented.
Implementation perspective
Treat External System Services as a CUI protection outcome that must be reflected in the system boundary, documented implementation, operational behavior, and assessment evidence. Pay particular attention to security requirements in acquisition, secure development, supplier expectations, and acceptance evidence.
- Confirm the requirement is in scope for the CUI system components, services, users, and external connections being assessed.
- Resolve every organization-defined parameter through an approved governance and tailoring process.
- Map each clause of the requirement to an accountable owner, implementation mechanism, and evidence source.
- Verify that inherited and shared implementations are supported by current provider evidence and responsibility boundaries.
- Collect evidence during normal operation and review changes, exceptions, and deficiencies on a risk-based cadence.
Questions to ask
- Which CUI assets, data flows, users, and services are protected by this requirement?
- Which portions are implemented locally, inherited, shared, or not applicable, and what evidence supports that determination?
- Do the system security plan, deployed configuration, operating process, and assessment evidence tell the same story?
- What change, incident, or threshold should trigger reassessment?
Evidence and validation
- security requirements in contracts and specifications
- architecture and design review records
- development lifecycle evidence
- supplier assessment and acceptance records
Common failure patterns
- security requirements added after procurement
- supplier claims accepted without evidence
- development exceptions becoming permanent
- security architecture not tied to testable requirements
Assessment objectives and methods
Assessment objectives (3)
- a.
the providers of external system services used for the processing, storage, or transmission of CUI comply with the following security requirements: [Organization-defined: security requirements].
- c.
processes, methods, and techniques to monitor security requirement compliance by external service providers on an ongoing basis are implemented.
- b.
user roles and responsibilities with regard to external system services, including shared responsibilities with external service providers, are defined and documented.
Examine
- system and services acquisition policy and procedures
- procedures for monitoring security requirement compliance by external service providers
- acquisition documentation
- contracts
- service-level agreements
- interagency agreements
- licensing agreements
- list of security requirements for external provider services
- assessment results or reports from external service providers
- SCRM plan
- system security plan
- other relevant documents or records
Interview
- personnel with acquisition responsibilities
- external providers of system services
- personnel with SCRM responsibilities
- personnel with information security responsibilities
Test
- organizational processes for monitoring security and privacy control compliance by external service providers on an ongoing basis
- mechanisms for monitoring security and privacy control compliance by external service providers on an ongoing basis
Source NIST SP 800-53 controls
These controls are referenced by the official SP 800-171 Rev. 3 OSCAL record. Open the corresponding control pages for complete control text, enhancements, D3FEND mappings, and related learning.
Authoritative sources
- NIST SP 800-171 Revision 3 official publication ↗
- NIST SP 800-171A Revision 3 official publication ↗
- NIST OSCAL Content release used for this import ↗
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. The official publications, the responsible federal agency, and the governing contract or agreement determine applicability, tailoring, assessment depth, and required implementation.