Frameworks / NIST SP 800-53 Revision 5.1 HIGH / SA-1 NIST SP 800-53 Revision 5.1 HIGH
SA System Services Acquisition
NIST SP 800-53 Revision 5.1 HIGH SA-1: Policy and Procedures Requires a system and services acquisition policy and supporting procedures to be developed, documented, disseminated, reviewed and updated on a defined cycle.
What else in your programme already covers this This control maps to 37 controls across 18 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
SOC2-CC5.3 COSO principle 12: Deploys control activities through policies and procedures SOC2-CC6.8 Controls to prevent or detect unauthorized or malicious software SOC2-CC7.1 Detection and monitoring procedures for security events are in place SOC2-CC7.2 Monitors system components for anomalies indicating malicious acts SOC2-CC7.3 Evaluates security events to determine incident status 5.24 Information security incident management planning and preparation 5.25 Assessment and decision on information security events 8.15 Logging 8.16 Monitoring activities NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved ASBv3-GS-10 Define and implement DevOps security strategy C5-DEV-01 Policies for the development/procurement of information systems 12.4 Logging and monitoring 12.4 Logging and monitoring 6.9.4 Logging and monitoring 10.2.1 Audit logs enabled on system components Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in SA System Services Acquisition Query this from an agent The graph holds this control, the 37 it maps to, and the evidence behind each claim, over MCP and REST.