id: "SA-04(06)" title: "Use of Information Assurance Products" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-04.06" priority: "P1" implementation_level: "organization" parent: "SA-04" enhancement: True


Employ only government off-the-shelf or commercial off-the-shelf information assurance and information assurance-enabled information technology products that compose an NSA-approved solution to protect classified information when the networks used to transmit the information are at a lower classification level than the information being transmitted; and

Ensure that these products have been evaluated and/or validated by NSA or in accordance with NSA-approved procedures.

Guidance

Commercial off-the-shelf IA or IA-enabled information technology products used to protect classified information by cryptographic means may be required to use NSA-approved key management. See NSA CSFC.

Assessment Objective: only government off-the-shelf or commercial off-the-shelf information assurance and information assurance-enabled information technology products that compose an NSA-approved solution to protect classified information when the networks used to transmit the information are at a lower classification level than the information being transmitted are employed;

Assessment Objective: these products have been evaluated and/or validated by NSA or in accordance with NSA-approved procedures.

Supply chain risk management plan

system and services acquisition policy

procedures addressing the integration of security requirements, descriptions, and criteria into the acquisition process

solicitation documents

acquisition documentation

acquisition contracts for the system, system component, or system service

security configurations to be implemented by the developer of the system, system component, or system service

service level agreements

list of deployed IT products/solutions

NSA-approved list

system security plan

other relevant documents or records

Organizational personnel with acquisition/contracting responsibilities

organizational personnel with the responsibility to determine system security requirements

organizational personnel responsible for ensuring information assurance products are NSA-approved and are evaluated and/or validated products in accordance with NSA-approved procedures

organizational personnel with information security responsibilities

Organizational processes for selecting and employing evaluated and/or validated information assurance products and services that compose an NSA-approved solution to protect classified information