NIST 800-53 SA-10 Mappings

Organizations consider the quality and completeness of configuration management activities conducted by developers as direct evidence of applying effective security controls. Controls include protecting the master copies of material used to generate security-relevant portions of the system hardware, software, and firmware from unauthorized modification or destruction. Maintaining the integrity of changes to the system, system component, or system service requires strict configuration control throughout the system development life cycle to track authorized changes and prevent unauthorized changes.

The configuration items that are placed under configuration management include the formal model; the functional, high-level, and low-level design specifications; other design data; implementation documentation; source code and hardware schematics; the current running version of the object code; tools for comparing new versions of security-relevant hardware descriptions and source code with previous versions; and test fixtures and documentation. Depending on the mission and business needs of organizations and the nature of the contractual relationships in place, developers may provide configuration management support during the operations and maintenance stage of the system development life cycle.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name
SA-10 Developer Configuration Management Protects T1078.001 Default Accounts
SA-10 Developer Configuration Management Protects T1078.003 Local Accounts
SA-10 Developer Configuration Management Protects T1195.003 Compromise Hardware Supply Chain
SA-10 Developer Configuration Management Protects T1213.003 Code Repositories
SA-10 Developer Configuration Management Protects T1495 Firmware Corruption
SA-10 Developer Configuration Management Protects T1505 Server Software Component
SA-10 Developer Configuration Management Protects T1505.001 SQL Stored Procedures
SA-10 Developer Configuration Management Protects T1505.002 Transport Agent
SA-10 Developer Configuration Management Protects T1505.004 IIS Components
SA-10 Developer Configuration Management Protects T1542 Pre-OS Boot
SA-10 Developer Configuration Management Protects T1542.004 ROMMONkit
SA-10 Developer Configuration Management Protects T1542.005 TFTP Boot
SA-10 Developer Configuration Management Protects T1553 Subvert Trust Controls
SA-10 Developer Configuration Management Protects T1553.006 Code Signing Policy Modification
SA-10 Developer Configuration Management Protects T1559.003 XPC Services
SA-10 Developer Configuration Management Protects T1564.009 Resource Forking
SA-10 Developer Configuration Management Protects T1574.002 DLL Side-Loading
SA-10 Developer Configuration Management Protects T1601 Modify System Image
SA-10 Developer Configuration Management Protects T1601.001 Patch System Image
SA-10 Developer Configuration Management Protects T1601.002 Downgrade System Image
SA-10 Developer Configuration Management Protects T1647 Plist File Modification
SA-10 Developer Configuration Management Protects T1072 Software Deployment Tools
SA-10 Developer Configuration Management Protects T1542.003 Bootkit
SA-10 Developer Configuration Management Protects T1542.001 System Firmware
SA-10 Developer Configuration Management Protects T1078 Valid Accounts
SA-10 Developer Configuration Management Protects T1078.004 Cloud Accounts