id: "SA-04(05)" title: "System, Component, and Service Configurations" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-04.05" priority: "P1" implementation_level: "organization" parent: "SA-04" enhancement: True
Statement
Require the developer of the system, system component, or system service to:
Deliver the system, component, or service with {{ insert: param, sa-04.05_odp }} implemented; and
Use the configurations as the default for any subsequent system, component, or service reinstallation or upgrade.
Guidance
Examples of security configurations include the U.S. Government Configuration Baseline (USGCB), Security Technical Implementation Guides (STIGs), and any limitations on functions, ports, protocols, and services. Security characteristics can include requiring that default passwords have been changed.
Assessment Objective: the developer of the system, system component, or system service is required to deliver the system, component, or service with {{ insert: param, sa-04.05_odp }} implemented;
Assessment Objective: the configurations are used as the default for any subsequent system, component, or service reinstallation or upgrade.
System and services acquisition policy
procedures addressing the integration of security requirements, descriptions, and criteria into the acquisition process
solicitation documents
acquisition documentation
acquisition contracts for the system, system component, or system service
security configurations to be implemented by the developer of the system, system component, or system service
service level agreements
system security plan
other relevant documents or records
Organizational personnel with acquisition/contracting responsibilities
organizational personnel with the responsibility to determine system security requirements
system developers or service provider
organizational personnel with information security responsibilities
Mechanisms used to verify that the configuration of the system, component, or service is delivered as specified