EvidenceSheet

SA-22 Unsupported System Components

Requires system components to be replaced once the developer, vendor or manufacturer no longer provides support, or alternative sources of continued support to be provided, with documented justification and approval wher

6
artefacts
0
held by a system
1
at each review
hard
to go live
Vendor register / contract repository
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

none for this control

periodic reviewEvidence produced at each review

  • Records of components actually replaced once vendor support ended, with dates · Vendor register / contract repository

governing documentDocuments that govern the control

  • Policy and procedures covering replacement, or justified continued use, of unsupported system components · Policy repository / GRC workspace
  • Hardware and software inventory recording vendor support status and end of support dates per component · Vendor register / contract repository
  • Documented approvals carrying the justification for each unsupported component still in use, and the compensating measures relied on · Document repository
  • Contracts or agreements evidencing alternative continued support, in house or from an external provider, for components the vendor no longer supports · Vendor register / contract repository
  • System security plan and supply chain risk management plan sections identifying unsupported components and the plan for them · Policy repository / GRC workspace

First move

This control is evidenced by people and documents, not systems. Put the document under version control with an owner and review date, and log each review as a record with reviewer and date. Do not try to automate it.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

SA-21 Developer Screening. Require that the developer of [organization-defined]: Has appropriate access authorizations as determined by assigned [organization-defined] ; and Satisfies the following additional personnel screening criteria: [organization-defined] · SA-23 Specialization. Employ [organization-defined] on [organization-defined] supporting mission essential services or functions to increase the trustworthiness in those systems or components