id: "SA-10(05)" title: "Mapping Integrity for Version Control" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-10.05" priority: "P1" implementation_level: "organization" parent: "SA-10" enhancement: True
Statement
Require the developer of the system, system component, or system service to maintain the integrity of the mapping between the master build data describing the current version of security-relevant hardware, software, and firmware and the on-site master copy of the data for the current version.
Guidance
Mapping integrity for version control addresses changes to hardware, software, and firmware components during both initial development and system development life cycle updates. Maintaining the integrity between the master copies of security-relevant hardware, software, and firmware (including designs, hardware drawings, source code) and the equivalent data in master copies in operational environments is essential to ensuring the availability of organizational systems that support critical mission and business functions.
Assessment Objective
the developer of the system, system component, or system service is required to maintain the integrity of the mapping between the master build data describing the current version of security-relevant hardware, software, and firmware and the on-site master copy of the data for the current version.
System and services acquisition policy
procedures addressing system developer configuration management
solicitation documentation
acquisition documentation
service level agreements
acquisition contracts for the system, system component, or system service
system developer configuration management plan
change control records
configuration management records
version control change/update records
integrity verification records between master copies of security-relevant hardware, software, and firmware (including designs and source code)
system security plan
other relevant documents or records
Organizational personnel with system and service acquisition responsibilities
organizational personnel with information security responsibilities
organizational personnel with configuration management responsibilities
system developers
Organizational processes for monitoring developer configuration management
mechanisms supporting and/or implementing the monitoring of developer configuration management