SA-2 Allocation of Resources
Determine the high-level information security and privacy requirements for the system or system service in mission and business process planning; determine, document and allocate the resources required to protect the sys
6
artefacts
0
held by a system
1
at each review
hard
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
- Records of review of the allocation when requirements or the system change across the system development life cycle · Document repository
governing documentDocuments that govern the control
- Mission and business process planning documentation recording the high-level information security and privacy requirements determined for the system or system service · Policy repository / GRC workspace
- Capital planning and investment control submission or business case showing the resources determined, documented and allocated to protect the system or system service · Document repository
- Programming and budgeting documentation showing a discrete line item for information security and privacy · Policy repository / GRC workspace
- Approved budget or spend plan carrying that line item, with its approval record · Policy repository / GRC workspace
- System security and privacy plan section recording the allocated resources and the basis for the amount · Policy repository / GRC workspace
First move
This control is evidenced by people and documents, not systems. Put the document under version control with an owner and review date, and log each review as a record with reviewer and date. Do not try to automate it.
Common gaps auditors find
- Security and privacy requirements determined after the acquisition decision rather than during mission and business process planning
- Security funding absorbed into a general IT or infrastructure line, so no discrete information security and privacy item exists to evidence
- Resources named in a plan but never traced through to an approved budget or capital planning submission
- Privacy resourcing omitted while security resourcing is documented, although the control covers both
- Line item established once at authorization and not maintained through sustainment and supply chain activity
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetSA-1 Policy and Procedures · SA-3 System Development Life Cycle