πΌ SA-4 ACQUISITION PROCESS
- Contextual name: πΌ SA-4 ACQUISITION PROCESS
- ID:
/frameworks/nist-sp-800-53-r4/sa/04
- Located in: πΌ SA SYSTEM AND SERVICES ACQUISITION
Descriptionβ
The organization includes the following requirements, descriptions, and criteria, explicitly or by reference, in the acquisition contract for the information system, system component, or information system service in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, standards, guidelines, and organizational mission/business needs: SA-4a. Security functional requirements; SA-4b. Security strength requirements; SA-4c. Security assurance requirements; SA-4d. Security-related documentation requirements; SA-4e. Requirements for protecting security-related documentation; SA-4f. Description of the information system development environment and environment in which the system is intended to operate; and SA-4g. Acceptance criteria.
Similarβ
- Internal
- ID:
dec-c-f7f1f31e
- ID:
Similar Sections (Give Policies To)β
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ NIST CSF v1.1 β πΌ DE.CM-6: External service provider activity is monitored to detect potential cybersecurity events | 7 | 7 | ||
πΌ NIST CSF v1.1 β πΌ PR.IP-2: A System Development Life Cycle to manage systems is implemented | 6 | 6 |