Skip to main content

💼 SA-10 Developer Configuration Management (M)(H)

  • Contextual name: 💼 SA-10 Developer Configuration Management (M)(H)
  • ID: /frameworks/fedramp-moderate-security-controls/sa/10
  • Located in: 💼 System and Services Acquisition

Description

Require the developer of the system, system component, or system service to:

a. Perform configuration management during system, component, or service [FedRAMP Assignment: development, implementation, AND operation];

b. Document, manage, and control the integrity of changes to [Assignment: organization-defined configuration items under configuration management];

c. Implement only organization-approved changes to the system, component, or service;

d. Document approved changes to the system, component, or service and the potential security and privacy impacts of such changes; and

e. Track security flaws and flaw resolution within the system, component, or service and report findings to [Assignment: organization-defined personnel].

SA-10 Additional FedRAMP Requirements and Guidance:

(e) Requirement: track security flaws and flaw resolution within the system, component, or service and report findings to organization-defined personnel, to include FedRAMP.

Similar

  • Sections
    • /frameworks/fedramp-high-security-controls/sa/10
  • Internal
    • ID: dec-c-51b9180e

Similar Sections (Take Policies From)

SectionSub SectionsInternal RulesPoliciesFlags
💼 FedRAMP High Security Controls → 💼 SA-10 Developer Configuration Management (M)(H)3

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlags

Policies (3)

PolicyLogic CountFlags
📝 Google Cloud SQL Server Instance 3625 (trace flag) Database Flag is not set to on 🟢1🟢 x6
📝 Google Cloud SQL Server Instance user connections Database Flag is set to a limiting (other than 0) value 🟢1🟢 x6
📝 Google Cloud SQL Server Instance user options Database Flag is configured 🟢1🟢 x6