πΌ SA-10 DEVELOPER CONFIGURATION MANAGEMENT
- Contextual name: πΌ SA-10 DEVELOPER CONFIGURATION MANAGEMENT
- ID:
/frameworks/nist-sp-800-53-r4/sa/10
- Located in: πΌ SA SYSTEM AND SERVICES ACQUISITION
Descriptionβ
The organization requires the developer of the information system, system component, or information system service to: SA-10a. Perform configuration management during system, component, or service [Selection (one or more): design; development; implementation; operation]; SA-10b. Document, manage, and control the integrity of changes to [Assignment: organization-defined configuration items under configuration management]; SA-10c. Implement only organization-approved changes to the system, component, or service; SA-10d. Document approved changes to the system, component, or service and the potential security impacts of such changes; and SA-10e. Track security flaws and flaw resolution within the system, component, or service and report findings to [Assignment: organization-defined personnel].
Similarβ
- Internal
- ID:
dec-c-aa4bca84
- ID:
Similar Sections (Give Policies To)β
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ NIST CSF v1.1 β πΌ PR.DS-8: Integrity checking mechanisms are used to verify hardware integrity | ||||
πΌ NIST CSF v1.1 β πΌ PR.IP-1: A baseline configuration of information technology/industrial control systems is created and maintained incorporating security principles (e.g. concept of least functionality) | 4 | 14 | ||
πΌ NIST CSF v1.1 β πΌ PR.IP-2: A System Development Life Cycle to manage systems is implemented | 6 | 6 | ||
πΌ NIST CSF v1.1 β πΌ PR.IP-3: Configuration change control processes are in place | 4 | 4 |
Sub Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ SA-10 (1) SOFTWARE _ FIRMWARE INTEGRITY VERIFICATION | ||||
πΌ SA-10 (2) ALTERNATIVE CONFIGURATION MANAGEMENT PROCESSES | ||||
πΌ SA-10 (3) HARDWARE INTEGRITY VERIFICATION | ||||
πΌ SA-10 (4) TRUSTED GENERATION | ||||
πΌ SA-10 (5) MAPPING INTEGRITY FOR VERSION CONTROL | ||||
πΌ SA-10 (6) TRUSTED DISTRIBUTION |