NIST SP 800-53 Rev 5
SA - System and Services Acquisition

NIST SP 800-53 Rev 5 NIST800-SA-10: SA-10 Developer Configuration Management

Require the developer of the system, system component, or system service to: a. Perform configuration management during system, component, or service [Selection (one or more): design; development; implementation; operation; disposal]; b. Document, manage, and control the integrity of changes to [Assignment: organization-defined configuration items under configuration management]; c. Implement only organization-approved changes to the system, component, or service; d. Document approved changes to the system, component, or service and the potential security and privacy impacts of such changes; and e. Track security flaws and flaw resolution within the system, component, or service and report findings to [Assignment: organization-defined personnel].

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 107 controls across 52 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 4 controls

  • CIS-16.1 Establish and Maintain a Secure Application Development Process
  • CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure
  • CIS-16.8 Separate Production and Non-Production Systems
  • CIS-4.1 Establish and Maintain a Secure Configuration Process

ISO 27001:2022 · 4 controls

  • 8.25 Secure development life cycle
  • 8.30 Outsourced development
  • 8.32 Change management
  • 8.9 Configuration management

ISO 27002:2022 · 4 controls

  • 8.25 Secure development life cycle
  • 8.30 Outsourced development
  • 8.32 Change management
  • 8.9 Configuration management
  • NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles
  • NIST-CSF-PR.DS-11 Backups of data are created, protected, maintained, and tested
  • NIST-CSF-PR.PS-01 Configuration management practices are established and applied
  • NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle

PCI DSS 4.0 · 4 controls

  • 1.2.8 1.2.8 NSC configuration files secured and consistent
  • 6.5.1 6.5.1 Change control procedure for production
  • 6.5.3 6.5.3 Separate pre-production from production
  • 6.5.4 6.5.4 Separate roles between production and pre-production
  • ASD37-04 User application hardening (Essential)
  • ASD37-10 Server application hardening (Very Good)
  • ASD37-11 Operating system hardening (Very Good)

BSI IT-Grundschutz · 3 controls

  • BSI-23 Baseline configuration establishment
  • BSI-24 Configuration change control
  • BSI-26 System component inventory

NIST SP 800-218 · 3 controls

API 1164 · 2 controls

  • API1164-14 Physical Security
  • API1164-22 Configuration management for OT systems
  • ASBv3-DS-3 Secure DevOps infrastructure
  • DS-6 Enforce security of workload throughout DevOps lifecycle

C5 (Germany) · 2 controls

  • CCM-AIS-06 Automated Secure Application Deployment
  • CCM-CCC-01 Change Management Policy and Procedures

FedRAMP High · 2 controls

  • SA-10 Developer Configuration Management
  • SA-22 Unsupported System Components (SA-22)

FedRAMP Moderate · 2 controls

  • SA-10 Developer Configuration Management
  • SA-22 Unsupported System Components (SA-22)

FedRAMP Rev 5 · 2 controls

  • FEDRAMP-CM-1 Configuration Management Policy
  • FEDRAMP-CM-2 Baseline Configuration
  • IEC62304-4.1 Quality Management System
  • IEC62304-5.1 Software Development Planning

IEC 62443 · 2 controls

  • IEC62443-14 System security hardening
  • IEC62443-22 Configuration management for OT systems

ISO 27701:2019 · 2 controls

  • 6.11.2 Security in development and support processes
  • 6.9.5 Control of operational software

ISO/IEC 27019:2024 · 2 controls

  • ISO27019-14 System security hardening
  • ISO27019-22 Configuration management for OT systems

NIST SP 1800-32 · 2 controls

NIST SP 800-190 · 2 controls

  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection
  • AS9100D-8.1 Operational Planning and Control
  • Clause 10 Change and configuration management
  • SUP.8 Configuration Management
  • CA-ITSG33-SC-01 Security Control Catalogue

EU AI Act · 1 control

  • CJIS-7 Configuration Management
  • CAT-D3-3 Corrective controls
  • FFIEC-10 Secure configuration standards
  • ISO-26262-8-7 Configuration management
  • ISO20000-10 Configuration management

ISO/IEC 27400:2022 · 1 control

  • 27400-6.4 Default Configuration Security

ITIL 4 · 1 control

  • ITIL4-10 Configuration management
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • SA-10 SA-10 Developer Configuration Management
  • SA-10 SA-10 Developer Configuration Management

OSFI B-13 · 1 control

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery
  • OMANCS-5 Network, Endpoint, System Development, and Configuration Security
  • OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management

PCI P2PE · 1 control

  • PCI-P2PE-10 Secure configuration standards

PCI PIN Security · 1 control

  • PCI-PIN-10 Secure configuration standards

PCI SSF · 1 control

  • PCI-SSF-10 Secure configuration standards

PSD2 SCA · 1 control

  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication

SOC 2 · 1 control

  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure
  • CISABD-1 Take Ownership of Customer Security Outcomes

South Korea ISMS-P · 1 control

  • ISMSP-SYS-01 System Hardening and Patch Management

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in SA - System and Services Acquisition

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-SA-10 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 107 it maps to, and the evidence behind each claim, over MCP and REST.