STIGhub
STIGs
RMF Controls
Compare
← All Controls
SA-1
System and Services Acquisition
Rev 5
Policy and Procedures
CCI Identifiers (21)
CCI-000601
Defines the frequency with which to review and update the current system and services acquisition policy.
CCI-000602
Develop and document an organization-level; mission/business process-level; and/or system-level system and services acquisition policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance.
CCI-000603
Disseminate to organization-defined personnel or roles an organization-level; mission/business process-level; and/or system-level system and services acquisition policy.
CCI-000604
Review and update the current system and services acquisition policy in accordance with organization-defined frequency.
CCI-000605
Develop and document procedures to facilitate the implementation of the system and services acquisition policy and associated system and services acquisition controls.
CCI-000606
Disseminate to organization-defined personnel or roles procedures to facilitate the implementation of the system and services acquisition policy and associated system and services acquisition controls.
CCI-000607
Review and update the current system and services acquisition procedures in accordance with organization-defined frequency.
CCI-001646
Defines the frequency with which to review and update the current system and services acquisition procedures.
CCI-003089
Defines the personnel or roles to whom the organization-level; mission/business process-level; and/or system-level system and services acquisition policy is disseminated.
CCI-003090
Defines the personnel or roles to whom procedures to facilitate the implementation of the system and services acquisition policy and associated system and services acquisition controls are disseminated.
CCI-004655
Develop and document an organization-level; mission/business process-level; and/or system-level system and services acquisition policy that is consistent with applicable laws, Executive Orders, directives, regulations, polices, standards, and guidelines.
CCI-004656
Designate an organization-defined official to manage development and documentation of the system and services acquisition policy.
CCI-004657
Designate an organization-defined official to manage dissemination of the system and services acquisition policy.
CCI-004658
Defines the official designated to manage development and documentation of the system and services acquisition policy.
CCI-004659
Designate an organization-defined official to manage the development and documentation of the system and services acquisition procedures.
CCI-004660
Designate an organization-defined official to manage the dissemination of the system and services acquisition procedures.
CCI-004661
Defines the official designated to manage the system and services acquisition procedures.
CCI-004662
Review and update the current system and services acquisition policy following organization-defined events.
CCI-004663
Defines the events following reviewing and updating the current system and services acquisition policy.
CCI-004664
Review and update the current system and services acquisition procedures following organization-defined events.
CCI-004665
Defines the events following reviewing and updating the current system and services acquisition procedures.
Linked STIG Checks (0)
No STIG checks reference this control.