SA-22 Unsupported System Components

System and Services Acquisition

New in Rev 5

Description

a. Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer; or b. Provide the following options for alternative sources for continued support for unsupported components [Selection (one or more): in-house support; [Assignment: organization-defined support from external providers]].

Supplemental Guidance

Support for system components includes software patches, firmware updates, replacement parts, and maintenance contracts. An example of unsupported components includes when vendors no longer provide critical software patches or updates for their products. Unsupported components can create security vulnerabilities. Policies may be developed to eliminate the use of unsupported system components.

Changes from Rev 4

New control in Rev 5.

Compliance Mappings

ISO 27001:2022

A.8.19

ISO 27002:2022

8.19

COBIT 2019

BAI09

CIS Controls v8

CIS 12.1CIS 16.5CIS 2CIS 2.2CIS 9.1

NIST CSF 2.0

ID.AM-08PR.PS-02PR.PS-03

ASD Essential Eight

E8-6E8-6 ML3

EU DORA

Art.8(5)

BIO2

8.19

RBI CSF

Annex1.2Annex1.7

HKMA TM-E-1

TME1.3.4

DNB Good Practice

DNB.19.3

EU CRA

CRA.I.2cCRA.II.2CRA.Info.7

SWIFT CSCF

SWIFT.2.2

SAMA CSF

3.23.5

NCA ECC

2-102-3

UAE IA

T10

CBB TM

TM-15

Qatar NIA

SD

CBUAE

CR-12

CBE CSF

CRM-2CTO-9OVM-1

SA JS2

JS2-8.5JS2-8.7

CBN CSF

Part2.4

BoG CISD

CISD-XVI

BoM CTRM

3.7

IOSCO Cyber Resilience

PROT-7

FFIEC IS

II.C.11II.C.14

NYDFS 500

500.13

ECB CROE

CROE.2.3.4CROE.2.8.2

EBA ICT Guidelines

3.5(b)

SEBI CSCRF

GV.SC

BOT Cyber Resilience

Ch2.5

NERC CIP

CIP-013-2

TSA Pipeline SD

SD-2 Sec D

IEEE 1686-2022

5.10

FERC CIP Orders

Order 829

NAIC Insurance Data Security

4-asset

FDA Cybersecurity Guidance

PU-2PU-3

NHS DSPT

NDG-8.1

OWASP MASVS v2.1

MASVS-CODE-1MASVS-CODE-2