SA-4 Acquisition process
Requires acquisition contracts for the system, component or service to include, directly or by reference and using standardised contract language, the security and privacy functional requirements, strength of mechanism a
4
artefacts
0
held by a system
1
at each review
hard
to go live
Vendor register / contract repository
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
- Documented acceptance criteria and the acceptance decision record · Document repository
governing documentDocuments that govern the control
- Contract or purchase agreement containing the required security and privacy requirement sets · Vendor register / contract repository
- Standardised contract language or clause library used in acquisition · Vendor register / contract repository
- Allocation of control responsibility between the organization and the supplier · Vendor register / contract repository
First move
This control is evidenced by people and documents, not systems. Put the document under version control with an owner and review date, and log each review as a record with reviewer and date. Do not try to automate it.
Common gaps auditors find
- Requirements sent to the supplier during evaluation but never written into the signed contract
- Acceptance criteria absent, so delivery is accepted on demonstration alone
- Responsibility for shared controls left ambiguous between the parties
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetSA-3 System development life cycle · SA-5 System documentation