Skip to main content

πŸ’Ό SA-5 System Documentation

Description​

a. Obtain or develop administrator documentation for the system, system component, or system service that describes:

  1. Secure configuration, installation, and operation of the system, component, or service;
  2. Effective use and maintenance of security and privacy functions and mechanisms; and
  3. Known vulnerabilities regarding configuration and use of administrative or privileged functions; b. Obtain or develop user documentation for the system, system component, or system service that describes:
  4. User-accessible security and privacy functions and mechanisms and how to effectively use those functions and mechanisms;
  5. Methods for user interaction, which enables individuals to use the system, component, or service in a more secure manner and protect individual privacy; and
  6. User responsibilities in maintaining the security of the system, component, or service and privacy of individuals; c. Document attempts to obtain system, system component, or system service documentation when such documentation is either unavailable or nonexistent and take [Assignment: organization-defined actions] in response; and d. Distribute documentation to [Assignment: organization-defined personnel or roles].

Similar​

  • Internal
    • ID: dec-c-ad59b8db

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό FedRAMP High Security Controls β†’ πŸ’Ό SA-5 System Documentation (L)(M)(H)
πŸ’Ό FedRAMP Low Security Controls β†’ πŸ’Ό SA-5 System Documentation (L)(M)(H)
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό ID.AM-02: Inventories of software, services, and systems managed by the organization are maintained7
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό ID.RA-09: The authenticity and integrity of hardware and software are assessed prior to acquisition and use

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό SA-5(1) System Documentation _ Functional Properties of Security Controls
πŸ’Ό SA-5(2) System Documentation _ Security-relevant External System Interfaces
πŸ’Ό SA-5(3) System Documentation _ High-level Design
πŸ’Ό SA-5(4) System Documentation _ Low-level Design
πŸ’Ό SA-5(5) System Documentation _ Source Code