Skip to content

SA-9.1: Risk Assessments and Organizational Approvals

An OSCAL Control

Statement

    • (a)

      Conduct an organizational assessment of risk prior to the acquisition or outsourcing of information security services; and

    • (b)

      Verify that the acquisition or outsourcing of dedicated information security services is approved by .