id: "SA-04(06)" title: "Use of Information Assurance Products" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-04.06" priority: "P1" implementation_level: "organization" parent: "SA-04" enhancement: True
Employ only government off-the-shelf or commercial off-the-shelf information assurance and information assurance-enabled information technology products that compose an NSA-approved solution to protect classified information when the networks used to transmit the information are at a lower classification level than the information being transmitted; and
Ensure that these products have been evaluated and/or validated by NSA or in accordance with NSA-approved procedures.
Guidance
Commercial off-the-shelf IA or IA-enabled information technology products used to protect classified information by cryptographic means may be required to use NSA-approved key management. See NSA CSFC.
Assessment Objective: only government off-the-shelf or commercial off-the-shelf information assurance and information assurance-enabled information technology products that compose an NSA-approved solution to protect classified information when the networks used to transmit the information are at a lower classification level than the information being transmitted are employed;
Assessment Objective: these products have been evaluated and/or validated by NSA or in accordance with NSA-approved procedures.
Supply chain risk management plan
system and services acquisition policy
procedures addressing the integration of security requirements, descriptions, and criteria into the acquisition process
solicitation documents
acquisition documentation
acquisition contracts for the system, system component, or system service
security configurations to be implemented by the developer of the system, system component, or system service
service level agreements
list of deployed IT products/solutions
NSA-approved list
system security plan
other relevant documents or records
Organizational personnel with acquisition/contracting responsibilities
organizational personnel with the responsibility to determine system security requirements
organizational personnel responsible for ensuring information assurance products are NSA-approved and are evaluated and/or validated products in accordance with NSA-approved procedures
organizational personnel with information security responsibilities
Organizational processes for selecting and employing evaluated and/or validated information assurance products and services that compose an NSA-approved solution to protect classified information