SA: System and Services Acquisition
OT Tailoring Considerations
In situations where the OT cannot support the specific system and services acquisition requirements of a control, the organization employs compensating controls in accordance with the general tailoring guidance. Examples of compensating controls are given with each control as appropriate.
Controls
SA-1: Policy and Procedures
Baseline(s):
- Low
- Moderate
- High
- Privacy
- OT Low (SP 800-82r3)
- OT Moderate (SP 800-82r3)
- OT High (SP 800-82r3)
Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]: [Assignment (one or more): organization-level, mission/business process-level, system-level] system and services acquisition policy that: Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and Procedures to facilitate…
SA-2: Allocation of Resources
Baseline(s):
- Low
- Moderate
- High
- Privacy
- OT Low (SP 800-82r3)
- OT Moderate (SP 800-82r3)
- OT High (SP 800-82r3)
Determine the high-level information security and privacy requirements for the system or system service in mission and business process planning; Determine, document, and allocate the resources required to protect the system or system service as part of the organizational capital planning and investment control process; and Establish a discrete line item for information security and…
SA-3: System Development Life Cycle
Baseline(s):
- Low
- Moderate
- High
- Privacy
- OT Low (SP 800-82r3)
- OT Moderate (SP 800-82r3)
- OT High (SP 800-82r3)
Acquire, develop, and manage the system using [Assignment: organization-defined system-development life cycle] that incorporates information security and privacy considerations; Define and document information security and privacy roles and responsibilities throughout the system development life cycle; Identify individuals having information security and privacy roles and responsibilities; and Integrate the organizational information security and privacy risk management…
SA-4: Acquisition Process
Baseline(s):
- Low
- Moderate
- High
- Privacy
- OT Low (SP 800-82r3)
- OT Moderate (SP 800-82r3)
- OT High (SP 800-82r3)
Include the following requirements, descriptions, and criteria, explicitly or by reference, using [Assignment (one or more): standardized contract language, [Assignment: organization-defined contract language] ] in the acquisition contract for the system, system component, or system service: Security and privacy functional requirements; Strength of mechanism requirements; Security and privacy assurance requirements; Controls needed to satisfy the…
SA-5: System Documentation
Baseline(s):
- Low
- Moderate
- High
- OT Low (SP 800-82r3)
- OT Moderate (SP 800-82r3)
- OT High (SP 800-82r3)
Obtain or develop administrator documentation for the system, system component, or system service that describes: Secure configuration, installation, and operation of the system, component, or service; Effective use and maintenance of security and privacy functions and mechanisms; and Known vulnerabilities regarding configuration and use of administrative or privileged functions; Obtain or develop user documentation for…
SA-8: Security and Privacy Engineering Principles
Baseline(s):
- Low
- Moderate
- High
- OT Low (SP 800-82r3)
- OT Moderate (SP 800-82r3)
- OT High (SP 800-82r3)
Apply the following systems security and privacy engineering principles in the specification, design, development, implementation, and modification of the system and system components: [Assignment: organization-defined systems security and privacy engineering principles].
SA-9: External System Services
Baseline(s):
- Low
- Moderate
- High
- Privacy
- OT Low (SP 800-82r3)
- OT Moderate (SP 800-82r3)
- OT High (SP 800-82r3)
Require that providers of external system services comply with organizational security and privacy requirements and employ the following controls: [Assignment: organization-defined controls]; Define and document organizational oversight and user roles and responsibilities with regard to external system services; and Employ the following processes, methods, and techniques to monitor control compliance by external service providers on…
SA-10: Developer Configuration Management
Baseline(s):
- Moderate
- High
- OT Moderate (SP 800-82r3)
- OT High (SP 800-82r3)
Require the developer of the system, system component, or system service to: Perform configuration management during system, component, or service [Assignment (one or more): design, development, implementation, operation, disposal]; Document, manage, and control the integrity of changes to [Assignment: organization-defined configuration items]; Implement only organization-approved changes to the system, component, or service; Document approved changes…
SA-11: Developer Testing and Evaluation
Baseline(s):
- Moderate
- High
- Privacy
- OT Moderate (SP 800-82r3)
- OT High (SP 800-82r3)
Require the developer of the system, system component, or system service, at all post-design stages of the system development life cycle, to: Develop and implement a plan for ongoing security and privacy control assessments; Perform [Assignment (one or more): unit, integration, system, regression] testing/evaluation [Assignment: organization-defined frequency to conduct] at [Assignment: organization-defined depth and coverage];…
SA-15: Development Process, Standards, and Tools
Baseline(s):
- Moderate
- High
- OT Moderate (SP 800-82r3)
- OT High (SP 800-82r3)
Require the developer of the system, system component, or system service to follow a documented development process that: Explicitly addresses security and privacy requirements; Identifies the standards and tools used in the development process; Documents the specific tool options and tool configurations used in the development process; and Documents, manages, and ensures the integrity of…
SA-16: Developer-provided Training
Baseline(s):
- High
- OT High (SP 800-82r3)
Require the developer of the system, system component, or system service to provide the following training on the correct use and operation of the implemented security and privacy functions, controls, and/or mechanisms: [Assignment: organization-defined training].
SA-17: Developer Security and Privacy Architecture and Design
Baseline(s):
- High
- OT High (SP 800-82r3)
Require the developer of the system, system component, or system service to produce a design specification and security and privacy architecture that: Is consistent with the organization’s security and privacy architecture that is an integral part the organization’s enterprise architecture; Accurately and completely describes the required security and privacy functionality, and the allocation of controls…
SA-20: Customized Development of Critical Components
Baseline(s):
Reimplement or custom develop the following critical system components: [Assignment: organization-defined critical system].
SA-21: Developer Screening
Baseline(s):
- High
- OT High (SP 800-82r3)
Require that the developer of [Assignment: organization-defined system, systems component, or system service]: Has appropriate access authorizations as determined by assigned [Assignment: organization-defined official government duties] ; and Satisfies the following additional personnel screening criteria: [Assignment: organization-defined additional personnel screening criteria].
SA-22: Unsupported System Components
Baseline(s):
- Low
- Moderate
- High
- OT Low (SP 800-82r3)
- OT Moderate (SP 800-82r3)
- OT High (SP 800-82r3)
Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer; or Provide the following options for alternative sources for continued support for unsupported components [Assignment (one or more): in-house support, [Assignment: organization-defined support from external providers] ].
SA-23: Specialization
Baseline(s):
Employ [Assignment (one or more): design modification, augmentation, reconfiguration] on [Assignment: organization-defined systems or system components] supporting mission essential services or functions to increase the trustworthiness in those systems or components.
SA-24: Design For Cyber Resiliency
Baseline(s):
Design organizational systems, system components, or system services to achieve cyber resiliency by: Defining the following cyber resiliency goals: [Assignment: organization-defined cyber resiliency goals]. Defining the following cyber resiliency objectives: [Assignment: organization-defined cyber resiliency objectives]. Defining the following cyber resiliency techniques: [Assignment: organization-defined cyber resiliency techniques]. Defining the following cyber resiliency implementation approaches: [Assignment: organization-defined…