|
controlSA-10

Developer Configuration Management (SA-10)

Require the developer of the system, system component, or system service to:

Security Baselines

MODERATEHIGHLOW
acquisitionsdlcservicessupply-chain

Why These Connect

Maps To5

These are equivalent or closely aligned requirements in other frameworks.

Baselined In2

This control is included in the linked security baseline (LOW, MODERATE, or HIGH).

Supports23

These related controls work together — a change to one may affect the others.

Enhances7

These enhancements add specific capabilities or refinements to the base control.

Cross-Framework Mappings(5)

ID.RA-09ID.RA-09Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.PS-06PR.PS-06Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20224 mappingsFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
ID.RA-09ID.RA-09Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.PS-06PR.PS-06Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5

Organization-Defined Parameters(3)

SelectionSelection (one-or-more): design / development / implementation / operation / disposal
Assignmentorganization-defined configuration items
Assignmentorganization-defined personnel

Control Enhancements(7)