NIST 800-53 Rev 5

424 controls available

SA-22lowmoderatehigh

Unsupported System Components

System and Services Acquisition

Control Statement

Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer; or Provide the following options for alternative sources for continued support for unsupported components {{ insert: param, sa-22_odp.01 }}.

Discussion

Support for system components includes software patches, firmware updates, replacement parts, and maintenance contracts. An example of unsupported components includes when vendors no longer provide critical software patches or product updates, which can result in an opportunity for adversaries to exploit weaknesses in the installed components. Exceptions to replacing unsupported system components include systems that provide critical mission or business capabilities where newer technologies are not available or where the systems are so isolated that installing replacement components is not an option. Alternative sources for support address the need to provide continued support for system components that are no longer supported by the original manufacturers, developers, or vendors when such components remain essential to organizational mission and business functions. If necessary, organizations can establish in-house support by developing customized patches for critical software components or, alternatively, obtain the services of external providers who provide ongoing support for the designated unsupported components through contractual relationships. Such contractual relationships can include open-source software value-added vendors. The increased risk of using unsupported system components can be mitigated, for example, by prohibiting the connection of such components to public or uncontrolled networks, or implementing other forms of isolation.

Framework
NIST SP 800-53 Rev 5
Family
System and Services Acquisition
Baselines
low, moderate, high

Related Frameworks

5 paths across 1 framework
CCI5 mappings
CCI-003372
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003373
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003374
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003375
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003376
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

35 STIGs reach this control through 5 CCIs. Expand a row to see the responsible NICE and O*NET roles.

Operating System — Desktop

1 STIG

Operating System — Server

2 STIGs

Operating System — Mainframe

1 STIG
Mainframe Product Security Requirements Guide
V3R42025-09-101 of 194 findings match

Network Device

5 STIGs

Database

18 STIGs
Database Security Requirements Guide
42024-12-041 of 142 findings match
Database Security Requirements Guide
V4R52026-02-261 of 142 findings match
Show 10 more STIGs in this category →

Web / Application Server

4 STIGs

Virtualization / Container

2 STIGs
Container Platform Security Requirements Guide
V2R42025-09-101 of 188 findings match
Virtual Machine Manager Security Requirements Guide
V2R32025-09-101 of 198 findings match

Endpoint Security Management

2 STIGs
Central Log Server Security Requirements Guide
V3R42026-02-121 of 127 findings match