Organizational Control: Information System Documentation
Control ID: SA-5 Information System Documentation | Family: System and Services Acquisition | Source: NIST 800-53r4 |
Control: The organization:
|
||
Supplemental Guidance: This control helps organizational personnel understand the implementation and operation of security controls associated with information systems, system components, and information system services. Organizations consider establishing specific measures to determine the quality/completeness of the content provided. The inability to obtain needed documentation may occur, for example, due to the age of the information system/component or lack of support from developers and contractors. In those situations, organizations may need to recreate selected documentation if such documentation is essential to the effective implementation or operation of security controls. The level of protection provided for selected information system, component, or service documentation is commensurate with the security category or classification of the system. For example, documentation associated with a key DoD weapons system or command and control system would typically require a higher level of protection than a routine administrative system. Documentation that addresses information system vulnerabilities may also require an increased level of protection. Secure operation of the information system, includes, for example, initially starting the system and resuming secure system operation after any lapse in system operation. Related Controls: CM-6, CM-8, PL-2, PL-4, PS-2, SA-3, SA-4 |
||
Control Enhancements: N/A | ||
References: N/A | ||
Mechanisms: | ||
Protocol Implementation Conformance Statements: N/A |