id: "SA-15(05)" title: "Attack Surface Reduction" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-15.05" priority: "P1" implementation_level: "organization" parent: "SA-15" enhancement: True


Statement

Require the developer of the system, system component, or system service to reduce attack surfaces to {{ insert: param, sa-15.05_odp }}.

Guidance

Attack surface reduction is closely aligned with threat and vulnerability analyses and system architecture and design. Attack surface reduction is a means of reducing risk to organizations by giving attackers less opportunity to exploit weaknesses or deficiencies (i.e., potential vulnerabilities) within systems, system components, and system services. Attack surface reduction includes implementing the concept of layered defenses, applying the principles of least privilege and least functionality, applying secure software development practices, deprecating unsafe functions, reducing entry points available to unauthorized users, reducing the amount of code that executes, and eliminating application programming interfaces (APIs) that are vulnerable to attacks.

Assessment Objective

the developer of the system, system component, or system service is required to reduce attack surfaces to {{ insert: param, sa-15.05_odp }}.

System and services acquisition policy

procedures addressing development process, standards, and tools

procedures addressing attack surface reduction

solicitation documentation

acquisition documentation

service level agreements

acquisition contracts for the system or system service

system design documentation

network diagram

system configuration settings and associated documentation establishing/enforcing organization-defined thresholds for reducing attack surfaces

list of restricted ports, protocols, functions, and services

system security plan

other relevant documents or records

Organizational personnel with system and service acquisition responsibilities

organizational personnel with information security responsibilities

organizational personnel responsible for attack surface reduction thresholds

system developer

Organizational processes for defining attack surface reduction thresholds