Allocation of Resources

✓ LOW ✓ MODERATE ✓ HIGH
1 Overlay 6 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Discussion (NIST Supplemental Guidance)

Resource allocation for information security and privacy includes funding for system and services acquisition, sustainment, and supply chain-related risks throughout the system development life cycle.

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for SA-2 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. the high-level information security requirements for the system or system service are determined in mission and business process planning;
  2. the high-level privacy requirements for the system or system service are determined in mission and business process planning;
  3. the resources required to protect the system or system service are determined and documented as part of the organizational capital planning and investment control process;
  4. the resources required to protect the system or system service are allocated as part of the organizational capital planning and investment control process;
  5. a discrete line item for information security is established in organizational programming and budgeting documentation;
  6. a discrete line item for privacy is established in organizational programming and budgeting documentation.

Examine

[SELECT FROM: System and services acquisition policy; system and services acquisition procedures; system and services acquisition strategy and plans; procedures addressing the allocation of resources to information security and privacy requirements; procedures addressing capital planning and investment control; organizational programming and budgeting documentation; system security plan; privacy plan; supply chain risk management policy; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with capital planning, investment control, organizational programming, and budgeting responsibilities; organizational personnel with information security and privacy responsibilities; organizational personnel with supply chain risk management responsibilities].

Test

[SELECT FROM: Organizational processes for determining information security and privacy requirements; organizational processes for capital planning, programming, and budgeting; mechanisms supporting and/or implementing organizational capital planning, programming, and budgeting].

Overlays

OT/ICS Overlay SP 800-82r3

NIST SP 800-82r3 Appendix F, Table 22. Blank baseline means the control/control enhancement is not selected in that initial OT baseline.

LOW

  • Base control: Included (matches standard baseline)

MODERATE

  • Base control: Included (matches standard baseline)

HIGH

  • Base control: Included (matches standard baseline)

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for SA-2. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • System and services acquisition policy
  • system and services acquisition strategy and plans
  • system security plan
  • privacy plan
  • supply chain risk management policy

Testing

  • Organizational processes for determining information security and privacy requirements
  • organizational processes for capital planning, programming, and budgeting
  • mechanisms supporting and/or implementing organizational capital planning, programming, and budgeting

Other Records

  • system and services acquisition procedures
  • procedures addressing the allocation of resources to information security and privacy requirements
  • procedures addressing capital planning and investment control
  • organizational programming and budgeting documentation
  • other relevant documents or records