Unsupported System Components
✓ LOW ✓ MODERATE ✓ HIGHRequirements NIST SOURCE
Requirement Context
This element is part of SA-22 — Unsupported System Components. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of SA-22 — Unsupported System Components. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Discussion (NIST Supplemental Guidance)
Support for system components includes software patches, firmware updates, replacement parts, and maintenance contracts. An example of unsupported components includes when vendors no longer provide critical software patches or product updates, which can result in an opportunity for adversaries to exploit weaknesses in the installed components. Exceptions to replacing unsupported system components include systems that provide critical mission or business capabilities where newer technologies are not available or where the systems are so isolated that installing replacement components is not an option. Alternative sources for support address the need to provide continued support for system components that are no longer supported by the original manufacturers, developers, or vendors when such components remain essential to organizational mission and business functions. If necessary, organizations can establish in-house support by developing customized patches for critical software components or, alternatively, obtain the services of external providers who provide ongoing support for the designated unsupported components through contractual relationships. Such contractual relationships can include open-source software value-added vendors. The increased risk of using unsupported system components can be mitigated, for example, by prohibiting the connection of such components to public or uncontrolled networks, or implementing other forms of isolation.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for SA-22 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- one or more of the following PARAMETER VALUES is/are selected: {in-house support; <SA-22_ODP[02] support from external providers>};
- support from external providers is defined (if selected);
- system components are replaced when support for the components is no longer available from the developer, vendor, or manufacturer;
- <SA-22_ODP[01] SELECTED PARAMETER VALUES> provide options for alternative sources for continued support for unsupported components.
Examine
[SELECT FROM: System and services acquisition policy; procedures addressing the replacement or continued use of unsupported system components; documented evidence of replacing unsupported system components; documented approvals (including justification) for the continued use of unsupported system components; system security plan; supply chain risk management plan; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with system and service acquisition responsibilities; organizational personnel with information security responsibilities; organizational personnel with the responsibility for the system development life cycle; organizational personnel responsible for component replacement].
Test
[SELECT FROM: Organizational processes for replacing unsupported system components; mechanisms supporting and/or implementing the replacement of unsupported system components].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for SA-22. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- System and services acquisition policy
- system security plan
- supply chain risk management plan
Testing
- Organizational processes for replacing unsupported system components
- mechanisms supporting and/or implementing the replacement of unsupported system components
Other Records
- procedures addressing the replacement or continued use of unsupported system components
- documented evidence of replacing unsupported system components
- documented approvals (including justification) for the continued use of unsupported system components
- other relevant documents or records