NIST 800-53 r5 · Controls catalogue · Family SA
SA-4Acquisition Process
Include the following requirements, descriptions, and criteria, explicitly or by reference, using {{ insert: param, sa-04_odp.01 }} in the acquisition contract for the system, system component, or system service: Security and privacy functional requirements; Strength of mechanism requirements; Security and privacy assurance requirements; Controls needed to satisfy the security and privacy requirements. Security and privacy documentation requirements; Requirements for protecting security and privacy documentation; Description of the system development environment and environment in which the system is intended to operate; Allocation of responsibility or identification of parties responsible for information security, privacy, and supply chain risk management; and Acceptance criteria.
Last updated: 20 August 2026 13:14 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: partial · 1 mapping(s) from 1 framework(s): OWASP-Web 1 (partial)
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (6)
- T1078 Valid Accounts Stealth, Persistence, Privilege Escalation, Initial Access
- T1078.001 Default Accounts Stealth, Persistence, Privilege Escalation, Initial Access
- T1078.003 Local Accounts Stealth, Persistence, Privilege Escalation, Initial Access
- T1078.004 Cloud Accounts Stealth, Persistence, Privilege Escalation, Initial Access
- T1134.005 SID-History Injection Stealth, Privilege Escalation
- T1574.001 DLL Stealth, Execution
Weaknesses this control addresses (7)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-798 | Use of Hard-coded Credentials | 2,000+ | Requiring security functional requirements and acceptance criteria allows contracts to prohibit hard-coded credentials in delivered systems or components. |
CWE-1188 | Initialization of a Resource with an Insecure Default | 300+ | Mandating secure configuration and initialization requirements in the acquisition process prevents delivery of products that initialize resources with insecure defaults. |
CWE-829 | Inclusion of Functionality from Untrusted Control Sphere | 300+ | Allocation of supply-chain risk management responsibilities and vetting of the development/operational environment reduce inclusion of functionality from untrusted control spheres. |
CWE-321 | Use of Hard-coded Cryptographic Key | 300+ | Functional and assurance requirements specified in acquisition can prohibit hard-coded cryptographic keys in delivered products. |
CWE-494 | Download of Code Without Integrity Check | 200+ | Requiring integrity-protection mechanisms and assurance requirements in contracts prevents acquisition of code-download features lacking integrity checks. |
CWE-1392 | Use of Default Credentials | 100+ | Security functional requirements and acceptance criteria can stipulate that acquired systems must not use default credentials. |
CWE-1104 | Use of Unmaintained Third Party Components | 26 | Explicit supply-chain risk management and acceptance criteria in acquisition contracts directly reduce procurement of unmaintained third-party components. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2024-36912 UPD | 6.9 | 9.6 | 0.0096 | partial |
CVE-2025-15480 UPD | 6.8 | 9.1 | 0.0031 | partial |
CVE-2024-36913 UPD | 6.6 | 9.3 | 0.0065 | partial |
CVE-2025-14551 UPD | 6.0 | 8.1 | 0.0028 | partial |
CVE-2026-66432 | 5.8 | 7.5 | 0.0040 | partial |
CVE-2026-52696 | 5.7 | 7.5 | 0.0024 | partial |
CVE-2025-32257 UPD | 4.6 | 5.3 | 0.0080 | partial |
CVE-2025-26482 UPD | 3.9 | 4.9 | 0.0029 | partial |
CVE-2026-26948 | 3.9 | 4.9 | 0.0029 | partial |