💼 SA-4 Acquisition Process
- ID:
/frameworks/nist-sp-800-53-r5/sa/04
Description​
Include the following requirements, descriptions, and criteria, explicitly or by reference, using [Selection (one or more): standardized contract language; [Assignment: organization-defined contract language]] in the acquisition contract for the system, system component, or system service: a. Security and privacy functional requirements; b. Strength of mechanism requirements; c. Security and privacy assurance requirements; d. Controls needed to satisfy the security and privacy requirements. e. Security and privacy documentation requirements; f. Requirements for protecting security and privacy documentation; g. Description of the system development environment and environment in which the system is intended to operate; h. Allocation of responsibility or identification of parties responsible for information security, privacy, and supply chain risk management; and i. Acceptance criteria.
Similar​
- Internal
- ID:
dec-c-e71cdc41
- ID:
Similar Sections (Give Policies To)​
Sub Sections​
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|---|---|---|---|---|
| 💼 SA-4(1) Acquisition Process _ Functional Properties of Controls | no data | ||||
| 💼 SA-4(2) Acquisition Process _ Design and Implementation Information for Controls | no data | ||||
| 💼 SA-4(3) Acquisition Process _ Development Methods, Techniques, and Practices | no data | ||||
| 💼 SA-4(4) Acquisition Process _ Assignment of Components to Systems | no data | ||||
| 💼 SA-4(5) Acquisition Process _ System, Component, and Service Configurations | no data | ||||
| 💼 SA-4(6) Acquisition Process _ Use of Information Assurance Products | no data | ||||
| 💼 SA-4(7) Acquisition Process _ NIAP-approved Protection Profiles | no data | ||||
| 💼 SA-4(8) Acquisition Process _ Continuous Monitoring Plan for Controls | no data | ||||
| 💼 SA-4(9) Acquisition Process _ Functions, Ports, Protocols, and Services in Use | no data | ||||
| 💼 SA-4(10) Acquisition Process _ Use of Approved PIV Products | no data | ||||
| 💼 SA-4(11) Acquisition Process _ System of Records | no data | ||||
| 💼 SA-4(12) Acquisition Process _ Data Ownership | no data |