SA-23 Specialization

System and Services Acquisition

New in Rev 5

Description

Employ [Assignment: organization-defined parameters] on [Assignment: organization-defined parameters] supporting mission essential services or functions to increase the trustworthiness in those systems or components.

Supplemental Guidance

It is often necessary for a system or system component that supports mission-essential services or functions to be enhanced to maximize the trustworthiness of the resource. Sometimes this enhancement is done at the design level. In other instances, it is done post-design, either through modifications of the system in question or by augmenting the system with additional components. For example, supplemental authentication or non-repudiation functions may be added to the system to enhance the identity of critical resources to other resources that depend on the organization-defined resources.

Changes from Rev 4

New control in Rev 5.

Compliance Mappings

BSI IT-Grundschutz

APP.3.1

ANSSI

SecNumCloud.15.3

FINMA Circular 2023/1

IV.F(100)V(102)V(103)

OSFI B-13

B-13.2.2

RBI CSF

Annex1.6

FISC Security Guidelines

FISC.O6