NIST 800-53 System and Services Acquisition Capability Group

All Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name
SA-10 Developer Configuration Management mitigates T1072 Software Deployment Tools
SA-10 Developer Configuration Management mitigates T1078 Valid Accounts
SA-10 Developer Configuration Management mitigates T1078.001 Default Accounts
SA-10 Developer Configuration Management mitigates T1078.003 Local Accounts
SA-10 Developer Configuration Management mitigates T1078.004 Cloud Accounts
SA-10 Developer Configuration Management mitigates T1195.001 Compromise Software Dependencies and Development Tools
SA-10 Developer Configuration Management mitigates T1213.003 Code Repositories
SA-10 Developer Configuration Management mitigates T1542 Pre-OS Boot
SA-10 Developer Configuration Management mitigates T1542.001 System Firmware
SA-10 Developer Configuration Management mitigates T1553 Subvert Trust Controls
SA-11 Developer Testing and Evaluation mitigates T1078 Valid Accounts
SA-15 Development Process, Standards, and Tools mitigates T1078 Valid Accounts
SA-17 Developer Security and Privacy Architecture and Design mitigates T1078 Valid Accounts
SA-03 System Development Life Cycle mitigates T1078 Valid Accounts
SA-04 Acquisition Process mitigates T1078 Valid Accounts
SA-16 Developer-provided Training mitigates T1078.001 Default Accounts
SA-15 Development Process, Standards, and Tools mitigates T1195.001 Compromise Software Dependencies and Development Tools
SA-22 Unsupported System Components mitigates T1195 Supply Chain Compromise
SA-22 Unsupported System Components mitigates T1195.001 Compromise Software Dependencies and Development Tools
SA-22 Unsupported System Components mitigates T1543 Create or Modify System Process
SA-22 Unsupported System Components mitigates T1543.002 Systemd Service
SA-09 External System Services mitigates T1072 Software Deployment Tools
SA-15 Development Process, Standards, and Tools mitigates T1078.001 Default Accounts
SA-15 Development Process, Standards, and Tools mitigates T1078.003 Local Accounts
SA-15 Development Process, Standards, and Tools mitigates T1078.004 Cloud Accounts
SA-15 Development Process, Standards, and Tools mitigates T1213.003 Code Repositories
SA-15 Development Process, Standards, and Tools mitigates T1528 Steal Application Access Token
SA-15 Development Process, Standards, and Tools mitigates T1552 Unsecured Credentials
SA-15 Development Process, Standards, and Tools mitigates T1552.001 Credentials In Files
SA-15 Development Process, Standards, and Tools mitigates T1552.004 Private Keys
SA-16 Developer-provided Training mitigates T1078.003 Local Accounts
SA-17 Developer Security and Privacy Architecture and Design mitigates T1078.001 Default Accounts
SA-17 Developer Security and Privacy Architecture and Design mitigates T1078.003 Local Accounts
SA-17 Developer Security and Privacy Architecture and Design mitigates T1078.004 Cloud Accounts
SA-03 System Development Life Cycle mitigates T1078.001 Default Accounts
SA-03 System Development Life Cycle mitigates T1078.003 Local Accounts
SA-03 System Development Life Cycle mitigates T1078.004 Cloud Accounts
SA-03 System Development Life Cycle mitigates T1213.003 Code Repositories
SA-04 Acquisition Process mitigates T1078.001 Default Accounts
SA-04 Acquisition Process mitigates T1078.003 Local Accounts
SA-04 Acquisition Process mitigates T1078.004 Cloud Accounts
SA-11 Developer Testing and Evaluation mitigates T1078.001 Default Accounts
SA-11 Developer Testing and Evaluation mitigates T1078.003 Local Accounts
SA-11 Developer Testing and Evaluation mitigates T1078.004 Cloud Accounts
SA-11 Developer Testing and Evaluation mitigates T1195.001 Compromise Software Dependencies and Development Tools
SA-11 Developer Testing and Evaluation mitigates T1213.003 Code Repositories
SA-11 Developer Testing and Evaluation mitigates T1528 Steal Application Access Token
SA-11 Developer Testing and Evaluation mitigates T1542 Pre-OS Boot
SA-11 Developer Testing and Evaluation mitigates T1542.001 System Firmware
SA-11 Developer Testing and Evaluation mitigates T1552 Unsecured Credentials
SA-11 Developer Testing and Evaluation mitigates T1552.001 Credentials In Files
SA-11 Developer Testing and Evaluation mitigates T1552.004 Private Keys
SA-11 Developer Testing and Evaluation mitigates T1553 Subvert Trust Controls
SA-08 Security and Privacy Engineering Principles mitigates T1078 Valid Accounts
SA-08 Security and Privacy Engineering Principles mitigates T1078.001 Default Accounts
SA-08 Security and Privacy Engineering Principles mitigates T1078.003 Local Accounts
SA-08 Security and Privacy Engineering Principles mitigates T1078.004 Cloud Accounts
SA-08 Security and Privacy Engineering Principles mitigates T1190 Exploit Public-Facing Application
SA-08 Security and Privacy Engineering Principles mitigates T1213.003 Code Repositories
SA-08 Security and Privacy Engineering Principles mitigates T1005 Data from Local System
SA-09 External System Services mitigates T1041 Exfiltration Over C2 Channel
SA-10 Developer Configuration Management mitigates T1195.003 Compromise Hardware Supply Chain
SA-10 Developer Configuration Management mitigates T1495 Firmware Corruption
SA-10 Developer Configuration Management mitigates T1505 Server Software Component
SA-10 Developer Configuration Management mitigates T1505.001 SQL Stored Procedures
SA-10 Developer Configuration Management mitigates T1505.002 Transport Agent
SA-10 Developer Configuration Management mitigates T1505.004 IIS Components
SA-10 Developer Configuration Management mitigates T1542.003 Bootkit
SA-10 Developer Configuration Management mitigates T1542.004 ROMMONkit
SA-10 Developer Configuration Management mitigates T1542.005 TFTP Boot
SA-10 Developer Configuration Management mitigates T1553.006 Code Signing Policy Modification
SA-10 Developer Configuration Management mitigates T1559.003 XPC Services
SA-10 Developer Configuration Management mitigates T1564.009 Resource Forking
SA-10 Developer Configuration Management mitigates T1574.002 DLL Side-Loading
SA-10 Developer Configuration Management mitigates T1601 Modify System Image
SA-10 Developer Configuration Management mitigates T1601.001 Patch System Image
SA-10 Developer Configuration Management mitigates T1601.002 Downgrade System Image
SA-10 Developer Configuration Management mitigates T1647 Plist File Modification
SA-22 Unsupported System Components mitigates T1189 Drive-by Compromise
SA-22 Unsupported System Components mitigates T1195.002 Compromise Software Supply Chain
SA-09 External System Services mitigates T1048 Exfiltration Over Alternative Protocol
SA-09 External System Services mitigates T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
SA-09 External System Services mitigates T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
SA-09 External System Services mitigates T1567 Exfiltration Over Web Service
SA-15 Development Process, Standards, and Tools mitigates T1552.002 Credentials in Registry
SA-15 Development Process, Standards, and Tools mitigates T1552.006 Group Policy Preferences
SA-15 Development Process, Standards, and Tools mitigates T1558.004 AS-REP Roasting
SA-15 Development Process, Standards, and Tools mitigates T1574.002 DLL Side-Loading
SA-16 Developer-provided Training mitigates T1574.002 DLL Side-Loading
SA-17 Developer Security and Privacy Architecture and Design mitigates T1134.005 SID-History Injection
SA-17 Developer Security and Privacy Architecture and Design mitigates T1482 Domain Trust Discovery
SA-17 Developer Security and Privacy Architecture and Design mitigates T1574.002 DLL Side-Loading
SA-03 System Development Life Cycle mitigates T1574.002 DLL Side-Loading
SA-04 Acquisition Process mitigates T1134.005 SID-History Injection
SA-04 Acquisition Process mitigates T1574.002 DLL Side-Loading
SA-11 Developer Testing and Evaluation mitigates T1134.005 SID-History Injection
SA-11 Developer Testing and Evaluation mitigates T1195.003 Compromise Hardware Supply Chain
SA-11 Developer Testing and Evaluation mitigates T1495 Firmware Corruption
SA-11 Developer Testing and Evaluation mitigates T1505 Server Software Component
SA-11 Developer Testing and Evaluation mitigates T1505.001 SQL Stored Procedures
SA-11 Developer Testing and Evaluation mitigates T1505.002 Transport Agent
SA-11 Developer Testing and Evaluation mitigates T1505.004 IIS Components
SA-11 Developer Testing and Evaluation mitigates T1542.003 Bootkit
SA-11 Developer Testing and Evaluation mitigates T1542.004 ROMMONkit
SA-11 Developer Testing and Evaluation mitigates T1542.005 TFTP Boot
SA-11 Developer Testing and Evaluation mitigates T1552.002 Credentials in Registry
SA-11 Developer Testing and Evaluation mitigates T1552.006 Group Policy Preferences
SA-11 Developer Testing and Evaluation mitigates T1553.006 Code Signing Policy Modification
SA-11 Developer Testing and Evaluation mitigates T1558.004 AS-REP Roasting
SA-11 Developer Testing and Evaluation mitigates T1559.003 XPC Services
SA-11 Developer Testing and Evaluation mitigates T1574.002 DLL Side-Loading
SA-11 Developer Testing and Evaluation mitigates T1601 Modify System Image
SA-11 Developer Testing and Evaluation mitigates T1601.001 Patch System Image
SA-11 Developer Testing and Evaluation mitigates T1601.002 Downgrade System Image
SA-11 Developer Testing and Evaluation mitigates T1612 Build Image on Host
SA-11 Developer Testing and Evaluation mitigates T1647 Plist File Modification
SA-08 Security and Privacy Engineering Principles mitigates T1025 Data from Removable Media
SA-08 Security and Privacy Engineering Principles mitigates T1041 Exfiltration Over C2 Channel
SA-08 Security and Privacy Engineering Principles mitigates T1048 Exfiltration Over Alternative Protocol
SA-08 Security and Privacy Engineering Principles mitigates T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
SA-08 Security and Privacy Engineering Principles mitigates T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
SA-08 Security and Privacy Engineering Principles mitigates T1052 Exfiltration Over Physical Medium
SA-08 Security and Privacy Engineering Principles mitigates T1052.001 Exfiltration over USB
SA-08 Security and Privacy Engineering Principles mitigates T1134.005 SID-History Injection
SA-08 Security and Privacy Engineering Principles mitigates T1482 Domain Trust Discovery
SA-08 Security and Privacy Engineering Principles mitigates T1559.003 XPC Services
SA-08 Security and Privacy Engineering Principles mitigates T1567 Exfiltration Over Web Service
SA-08 Security and Privacy Engineering Principles mitigates T1574.002 DLL Side-Loading
SA-08 Security and Privacy Engineering Principles mitigates T1647 Plist File Modification

Capabilities

Capability ID Capability Name Number of Mappings
SA-16 Developer-provided Training 3
SA-09 External System Services 6
SA-03 System Development Life Cycle 6
SA-17 Developer Security and Privacy Architecture and Design 7
SA-08 Security and Privacy Engineering Principles 20
SA-15 Development Process, Standards, and Tools 14
SA-10 Developer Configuration Management 27
SA-22 Unsupported System Components 6
SA-04 Acquisition Process 6
SA-11 Developer Testing and Evaluation 34