← Back to catalog
SA-4(12)
Data Ownership
System and Services Acquisition (SA)
Baselines
Low · Not includedModerate · Not includedHigh · Not included
Description
Include organizational data ownership requirements in the acquisition contract; and Require all data to be removed from the contractor’s system and returned to the organization within [assignment].
Discussion
Contractors who operate a system that contains data owned by an organization initiating the contract have policies and procedures in place to remove the data from their systems and/or return the data in a time frame defined by the contract.
Implementation guidance
No content available.
CSF 2.0 crosswalk
No CSF mappings exist for this control.