NIST 800-53 Rev 5
424 controls available
SA-2lowmoderatehighprivacy
Allocation of Resources
System and Services Acquisition
Control Statement
Determine the high-level information security and privacy requirements for the system or system service in mission and business process planning; Determine, document, and allocate the resources required to protect the system or system service as part of the organizational capital planning and investment control process; and Establish a discrete line item for information security and privacy in organizational programming and budgeting documentation.
Discussion
Resource allocation for information security and privacy includes funding for system and services acquisition, sustainment, and supply chain-related risks throughout the system development life cycle.
- Framework
- NIST SP 800-53 Rev 5
- Family
- System and Services Acquisition
- Baselines
- low, moderate, high, privacy
Related Frameworks
10 paths across 2 frameworks
Related Frameworks
SCF1 mapping
- Secure Controls Framework · 2026.2 · scf_strm · equivalent
CCI9 mappings
CCI-000610
1.00
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000611
1.00
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000612
1.00
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000613
1.00
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000614
1.00
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003091
1.00
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004666
1.00
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004667
1.00
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004668
1.00
- DISA · 2025-01-23 · disa_cci_list · equivalent
Related STIGs
No STIGs in the current catalog reference any CCI mapped to this control.