NIST SP 800-53 Rev 5 MODERATE
SA System and Services Acquisition

NIST SP 800-53 Rev 5 MODERATE SA-5: System Documentation

Obtain administrator and user documentation; protect; distribute to FedRAMP-defined personnel.

What else in your programme already covers this

This control maps to 21 controls across 13 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 4 controls

  • 10.2.1 Audit logs enabled on system components
  • 12.1.1 An overall information security policy is: • Established. • Published. • Maintained. • Disseminated to all relevant personnel, as well as to relevant vendors and business partners
  • 2.1.1 All security policies and operational procedures that are identified in Requirement 2 are: • Documented. • Kept up to date. • In use. • Known to all affected parties
  • 6.1.1 All security policies and operational procedures that are identified in Requirement 6 are: • Documented. • Kept up to date. • In use. • Known to all affected parties

SOC 2 · 3 controls

  • SOC2-CC2.1 COSO principle 13: Obtains and generates relevant, quality information
  • SOC2-CC2.2 COSO principle 14: Internally communicates information including objectives and responsibilities
  • SOC2-CC5.3 COSO principle 12: Deploys control activities through policies and procedures

C5 (Germany) · 2 controls

  • C5-PI-01 Documentation and safety of input and output interfaces
  • C5-PSS-01 Guidelines and Recommendations for Cloud Customers

ISO/IEC 42001:2023 · 2 controls

  • A.6.2.7 AI system technical documentation
  • A.8.2 System documentation and information for users

NIST SP 800-218 · 2 controls

CIS Controls v8 · 1 control

  • CIS-12.4 Establish and Maintain Architecture Diagram(s)

HIPAA Security Rule · 1 control

ISO 22301:2019 · 1 control

  • 7.5.3 Control of documented information

ISO 27001:2022 · 1 control

  • 5.37 Documented operating procedures

ISO 27002:2022 · 1 control

  • 5.37 Documented operating procedures

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in SA System and Services Acquisition

Query this from an agent

The graph holds this control, the 21 it maps to, and the evidence behind each claim, over MCP and REST.