NIST 800-53 Rev 5

424 controls available

SA-4lowmoderatehighprivacy

Acquisition Process

System and Services Acquisition

Control Statement

Include the following requirements, descriptions, and criteria, explicitly or by reference, using {{ insert: param, sa-04_odp.01 }} in the acquisition contract for the system, system component, or system service:

Discussion

Security and privacy functional requirements are typically derived from the high-level security and privacy requirements described in [SA-2](#sa-2) . The derived requirements include security and privacy capabilities, functions, and mechanisms. Strength requirements associated with such capabilities, functions, and mechanisms include degree of correctness, completeness, resistance to tampering or bypass, and resistance to direct attack. Assurance requirements include development processes, procedures, and methodologies as well as the evidence from development and assessment activities that provide grounds for confidence that the required functionality is implemented and possesses the required strength of mechanism. [SP 800-160-1](#e3cc0520-a366-4fc9-abc2-5272db7e3564) describes the process of requirements engineering as part of the system development life cycle. Controls can be viewed as descriptions of the safeguards and protection capabilities appropriate for achieving the particular security and privacy objectives of the organization and for reflecting the security and privacy requirements of stakeholders. Controls are selected and implemented in order to satisfy system requirements and include developer and organizational responsibilities. Controls can include technical, administrative, and physical aspects. In some cases, the selection and implementation of a control may necessitate additional specification by the organization in the form of derived requirements or instantiated control parameter values. The derived requirements and control parameter values may be necessary to provide the appropriate level of implementation detail for controls within the system development life cycle. Security and privacy documentation requirements address all stages of the system development life cycle. Documentation provides user and administrator guidance for the implementation and operation of controls. The level of detail required in such documentation is based on the security categorization or classification level of the system and the degree to which organizations depend on the capabilities, functions, or mechanisms to meet risk response expectations. Requirements can include mandated configuration settings that specify allowed functions, ports, protocols, and services. Acceptance criteria for systems, system components, and system services are defined in the same manner as the criteria for any organizational acquisition or procurement.

Framework
NIST SP 800-53 Rev 5
Family
System and Services Acquisition
Baselines
low, moderate, high, privacy

Related Frameworks

76 paths across 2 frameworks
SCF4 mappings
TDA-01Technology Development & Acquisition
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
TDA-02Minimum Viable Product (MVP) Security Requirements
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
TPM-01Third-Party Management
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
TPM-10Managing Changes To Third-Party Services
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
CCI72 mappings
CCI-003094
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003095
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003096
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003097
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003098
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003099
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003100
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004686
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004687
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004688
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent

+62 more (top 10 by confidence shown)

Related STIGs

2 STIGs reach this control through 50 CCIs. Expand a row to see the responsible NICE and O*NET roles.

Web / Application Server

2 STIGs