NIST SP 800-53 Rev 5 MODERATE
SA System and Services Acquisition

NIST SP 800-53 Rev 5 MODERATE SA-10: Developer Configuration Management

Require developer to perform CM during development, implementation, operation; document/track changes; implement only approved changes.

What else in your programme already covers this

This control maps to 33 controls across 13 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27002:2022 · 6 controls

  • 5.37 Documented operating procedures
  • 8.25 Secure development life cycle
  • 8.30 Outsourced development
  • 8.32 Change management
  • 8.4 Access to source code
  • 8.9 Configuration management

ISO 27001:2022 · 5 controls

  • 5.37 Documented operating procedures
  • 8.25 Secure development life cycle
  • 8.30 Outsourced development
  • 8.32 Change management
  • 8.9 Configuration management

PCI DSS 4.0 · 4 controls

  • 6.3.2 An inventory of bespoke and custom software, and third-party software components incorporated into bespoke and custom software is maintained to facilitate vulnerability and patch management
  • 6.5.1 Changes to all system components in the production environment are made according to established procedures that include: • Reason for, and description of, the change. • Documentation of security impact. • Documented change approval
  • 6.5.3 Pre-production environments are separated from production environments and the separation is enforced with access controls
  • 6.5.4 Roles and functions are separated between production and pre-production environments to provide accountability such that only reviewed and approved changes are deployed

C5 (Germany) · 3 controls

NIST SP 800-218 · 3 controls

  • ASBv3-DS-3 Secure DevOps infrastructure
  • DS-6 Enforce security of workload throughout DevOps lifecycle

NIST SP 800-53 Rev 5 · 2 controls

  • NIST800-SA-10 Developer configuration management
  • NIST800-SR-4 Provenance. Document, monitor, and maintain valid provenance of the following systems, system components, and associated data: [organization-defined]
  • SEC01-BP06 Automate deployment of standard security controls

CIS Controls v8 · 1 control

  • CIS-16.1 Establish and Maintain a Secure Application Development Process

ISO 27701:2019 · 1 control

  • 6.11.2 Security in development and support processes

SOC 2 · 1 control

  • SOC2-CC8.1 Change management processes are in place

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in SA System and Services Acquisition

Query this from an agent

The graph holds this control, the 33 it maps to, and the evidence behind each claim, over MCP and REST.