πΌ SA-10 Developer Configuration Management
- Contextual name: πΌ SA-10 Developer Configuration Management
- ID:
/frameworks/nist-sp-800-53-r5/sa/10
- Located in: πΌ SA System And Services Acquisition
Descriptionβ
Require the developer of the system, system component, or system service to: a. Perform configuration management during system, component, or service [Selection (one or more): design; development; implementation; operation; disposal]; b. Document, manage, and control the integrity of changes to [Assignment: organization-defined configuration items under configuration management]; c. Implement only organization-approved changes to the system, component, or service; d. Document approved changes to the system, component, or service and the potential security and privacy impacts of such changes; and e. Track security flaws and flaw resolution within the system, component, or service and report findings to [Assignment: organization-defined personnel].
Similarβ
- Internal
- ID:
dec-c-fcea8890
- ID:
Similar Sections (Give Policies To)β
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ FedRAMP High Security Controls β πΌ SA-10 Developer Configuration Management (M)(H) | ||||
πΌ NIST CSF v2.0 β πΌ ID.RA-09: The authenticity and integrity of hardware and software are assessed prior to acquisition and use |