id: "SA-04(05)" title: "System, Component, and Service Configurations" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-04.05" priority: "P1" implementation_level: "organization" parent: "SA-04" enhancement: True


Statement

Require the developer of the system, system component, or system service to:

Deliver the system, component, or service with {{ insert: param, sa-04.05_odp }} implemented; and

Use the configurations as the default for any subsequent system, component, or service reinstallation or upgrade.

Guidance

Examples of security configurations include the U.S. Government Configuration Baseline (USGCB), Security Technical Implementation Guides (STIGs), and any limitations on functions, ports, protocols, and services. Security characteristics can include requiring that default passwords have been changed.

Assessment Objective: the developer of the system, system component, or system service is required to deliver the system, component, or service with {{ insert: param, sa-04.05_odp }} implemented;

Assessment Objective: the configurations are used as the default for any subsequent system, component, or service reinstallation or upgrade.

System and services acquisition policy

procedures addressing the integration of security requirements, descriptions, and criteria into the acquisition process

solicitation documents

acquisition documentation

acquisition contracts for the system, system component, or system service

security configurations to be implemented by the developer of the system, system component, or system service

service level agreements

system security plan

other relevant documents or records

Organizational personnel with acquisition/contracting responsibilities

organizational personnel with the responsibility to determine system security requirements

system developers or service provider

organizational personnel with information security responsibilities

Mechanisms used to verify that the configuration of the system, component, or service is delivered as specified