SA-22 Unsupported System Components
Requires system components to be replaced once the developer, vendor or manufacturer no longer provides support, or alternative sources of continued support to be provided, with documented justification and approval wher
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
- Records of components actually replaced once vendor support ended, with dates · Vendor register / contract repository
governing documentDocuments that govern the control
- Policy and procedures covering replacement, or justified continued use, of unsupported system components · Policy repository / GRC workspace
- Hardware and software inventory recording vendor support status and end of support dates per component · Vendor register / contract repository
- Documented approvals carrying the justification for each unsupported component still in use, and the compensating measures relied on · Document repository
- Contracts or agreements evidencing alternative continued support, in house or from an external provider, for components the vendor no longer supports · Vendor register / contract repository
- System security plan and supply chain risk management plan sections identifying unsupported components and the plan for them · Policy repository / GRC workspace
First move
Common gaps auditors find
- Inventory lists components but never records the vendor end of support date, so nothing triggers replacement
- Unsupported components still running in production with no documented approval or justification on file
- An exception approved once and never re-reviewed, so a temporary acceptance became permanent
- Alternative support claimed for an unsupported component with no contract or in house capability behind it
- Replacement identified in a plan with no funded date, owner or tracking to completion
- Only software tracked for support status while firmware, hardware and embedded components are ignored
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetSA-21 Developer Screening. Require that the developer of [organization-defined]: Has appropriate access authorizations as determined by assigned [organization-defined] ; and Satisfies the following additional personnel screening criteria: [organization-defined] · SA-23 Specialization. Employ [organization-defined] on [organization-defined] supporting mission essential services or functions to increase the trustworthiness in those systems or components