System Documentation
✓ LOW ✓ MODERATE ✓ HIGHRequirements NIST SOURCE
- 1.Secure configuration, installation, and operation of the system, component, or service;
- 2.Effective use and maintenance of security and privacy functions and mechanisms; and
- 3.Known vulnerabilities regarding configuration and use of administrative or privileged functions;
Requirement Context
This element is part of SA-5 — System Documentation. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
- 1.User-accessible security and privacy functions and mechanisms and how to effectively use those functions and mechanisms;
- 2.Methods for user interaction, which enables individuals to use the system, component, or service in a more secure manner and protect individual privacy; and
- 3.User responsibilities in maintaining the security of the system, component, or service and privacy of individuals;
Requirement Context
This element is part of SA-5 — System Documentation. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of SA-5 — System Documentation. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of SA-5 — System Documentation. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Discussion (NIST Supplemental Guidance)
System artifacts and documentation created by the developer helps organizational personnel understand the implementation and operation of controls. Organizations consider establishing specific measures to determine the quality and completeness of the content provided. System documentation may be used to delineate roles, responsibilities and expectations of the developer and organization, support the management of supply chain risk, incident response, flaw remediation, and other functions. Personnel or roles that require documentation include system owners, system security officers, and system administrators. Attempts to obtain documentation include contacting manufacturers or suppliers and conducting web-based searches. The inability to obtain documentation may occur due to the age of the system or component or the lack of support from developers and contractors. When documentation cannot be obtained, organizations may need to recreate the documentation if it is essential to the implementation or operation of the controls. The protection provided for the documentation is commensurate with the security category or classification of the system. Documentation that addresses system vulnerabilities may require an increased level of protection. Secure operation of the system includes initially starting the system and resuming secure system operation after a lapse in system operation. An example of least privilege in software development is minimizing the functions that operate with elevated privileges (e.g., limiting the tools and functionality that operate in kernel mode)
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for SA-5 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- actions to take when system, system component, or system service documentation is either unavailable or nonexistent are defined;
- personnel or roles to distribute system documentation to is/are defined;
- administrator documentation for the system, system component, or system service that describes the secure configuration of the system, component, or service is obtained or developed;
- administrator documentation for the system, system component, or system service that describes the secure installation of the system, component, or service is obtained or developed;
- administrator documentation for the system, system component, or system service that describes the secure operation of the system, component, or service is obtained or developed;
- administrator documentation for the system, system component, or system service that describes the effective use of security functions and mechanisms is obtained or developed;
- administrator documentation for the system, system component, or system service that describes the effective maintenance of security functions and mechanisms is obtained or developed;
- administrator documentation for the system, system component, or system service that describes the effective use of privacy functions and mechanisms is obtained or developed;
- administrator documentation for the system, system component, or system service that describes the effective maintenance of privacy functions and mechanisms is obtained or developed;
- administrator documentation for the system, system component, or system service that describes known vulnerabilities regarding the configuration of administrative or privileged functions is obtained or developed;
- administrator documentation for the system, system component, or system service that describes known vulnerabilities regarding the use of administrative or privileged functions is obtained or developed;
- user documentation for the system, system component, or system service that describes user-accessible security functions and mechanisms is obtained or developed;
- user documentation for the system, system component, or system service that describes how to effectively use those (user-accessible security) functions and mechanisms is obtained or developed;
- user documentation for the system, system component, or system service that describes user-accessible privacy functions and mechanisms is obtained or developed;
- user documentation for the system, system component, or system service that describes how to effectively use those (user-accessible privacy) functions and mechanisms is obtained or developed;
- user documentation for the system, system component, or system service that describes methods for user interaction, which enable individuals to use the system, component, or service in a more secure manner is obtained or developed;
- user documentation for the system, system component, or system service that describes methods for user interaction, which enable individuals to use the system, component, or service to protect individual privacy is obtained or developed;
- user documentation for the system, system component, or system service that describes user responsibilities for maintaining the security of the system, component, or service is obtained or developed;
- user documentation for the system, system component, or system service that describes user responsibilities for maintaining the privacy of individuals is obtained or developed;
- attempts to obtain system, system component, or system service documentation when such documentation is either unavailable or nonexistent is documented;
- after attempts to obtain system, system component, or system service documentation when such documentation is either unavailable or nonexistent, <SA-05_ODP[01] actions> are taken in response;
- documentation is distributed to <SA-05_ODP[02] personnel or roles>.
Examine
[SELECT FROM: System and services acquisition policy; system and services acquisition procedures; procedures addressing system documentation; system documentation, including administrator and user guides; system design documentation; records documenting attempts to obtain unavailable or nonexistent system documentation; list of actions to be taken in response to documented attempts to obtain system, system component, or system service documentation; risk management strategy documentation; system security plan; privacy plan; privacy impact assessment; privacy risk assessment documentation; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with acquisition/contracting responsibilities; organizational personnel with information security and privacy responsibilities; system administrators; organizational personnel responsible for operating, using, and/or maintaining the system; system developers].
Test
[SELECT FROM: Organizational processes for obtaining, protecting, and distributing system administrator and user documentation].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for SA-5. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- System and services acquisition policy
- risk management strategy documentation
- system security plan
- privacy plan
Configuration
- system design documentation
Testing
- Organizational processes for obtaining, protecting, and distributing system administrator and user documentation
Other Records
- system and services acquisition procedures
- procedures addressing system documentation
- system documentation, including administrator and user guides
- records documenting attempts to obtain unavailable or nonexistent system documentation
- list of actions to be taken in response to documented attempts to obtain system, system component, or system service documentation
- privacy impact assessment
- privacy risk assessment documentation
- other relevant documents or records