NIST 800-53 Rev 5

424 controls available

SA-4(2)moderatehigh

Design and Implementation Information for Controls

System and Services Acquisition

Control Statement

Require the developer of the system, system component, or system service to provide design and implementation information for the controls that includes: {{ insert: param, sa-04.02_odp.01 }} at {{ insert: param, sa-04.02_odp.03 }}.

Discussion

Organizations may require different levels of detail in the documentation for the design and implementation of controls in organizational systems, system components, or system services based on mission and business requirements, requirements for resiliency and trustworthiness, and requirements for analysis and testing. Systems can be partitioned into multiple subsystems. Each subsystem within the system can contain one or more modules. The high-level design for the system is expressed in terms of subsystems and the interfaces between subsystems providing security-relevant functionality. The low-level design for the system is expressed in terms of modules and the interfaces between modules providing security-relevant functionality. Design and implementation documentation can include manufacturer, version, serial number, verification hash signature, software libraries used, date of purchase or download, and the vendor or download source. Source code and hardware schematics are referred to as the implementation representation of the system.

Framework
NIST SP 800-53 Rev 5
Family
System and Services Acquisition
Baselines
moderate, high

Related Frameworks

41 paths across 3 frameworks
SCF3 mappings
AST-04Network Diagrams & Data Flow Diagrams (DFDs)
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
TDA-04.1Functional Properties
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
TDA-20Access to Program Source Code
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
NIST 800-1714 mappings
3.12.1
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
3.12.2
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
3.12.3
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
3.12.4
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI33 mappings
CCI-003101
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003102
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003103
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003104
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003105
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003106
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000571
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000572
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000573
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000574
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent

+23 more (top 10 by confidence shown)

Related STIGs

2 STIGs reach this control through 50 CCIs. Expand a row to see the responsible NICE and O*NET roles.

Web / Application Server

2 STIGs