{"data":{"id":"SA-10","name":"Developer Configuration Management","family":"SA","family_name":"System and Services Acquisition","withdrawn":false,"description":"Require the developer of the system, system component, or system service to:\na. Perform configuration management during system, component, or service [Selection (one or more): design; development; implementation; operation; disposal];\nb. Document, manage, and control the integrity of changes to [Assignment: organization-defined configuration items under configuration management];\nc. Implement only organization-approved changes to the system, component, or service;\nd. Document approved changes to the system, component, or service and the potential security and privacy impacts of such changes; and\ne. Track security flaws and flaw resolution within the system, component, or service and report findings to [Assignment: organization-defined personnel].","supplemental_guidance":"Organizations consider the quality and completeness of configuration management activities conducted by developers as direct evidence of applying effective security controls. Controls include protecting the master copies of material used to generate security-relevant portions of the system hardware, software, and firmware from unauthorized modification or destruction. Maintaining the integrity of changes to the system, system component, or system service requires strict configuration control throughout the system development life cycle to track authorized changes and prevent unauthorized changes.\n\nThe configuration items that are placed under configuration management include the formal model; the functional, high-level, and low-level design specifications; other design data; implementation documentation; source code and hardware schematics; the current running version of the object code; tools for comparing new versions of security-relevant hardware descriptions and source code with previous versions; and test fixtures and documentation. Depending on the mission and business needs of organizations and the nature of the contractual relationships in place, developers may provide configuration management support during the operations and maintenance stage of the system development life cycle.","enhancements":[{"id":"SA-10(01)","name":"Software and Firmware Integrity Verification","statement":"Require the developer of the system, system component, or system service to enable integrity verification of software and firmware components.","baselines":[]},{"id":"SA-10(02)","name":"Alternative Configuration Management Processes","statement":"Provide an alternate configuration management process using organizational personnel in the absence of a dedicated developer configuration management team.","baselines":[]},{"id":"SA-10(03)","name":"Hardware Integrity Verification","statement":"Require the developer of the system, system component, or system service to enable integrity verification of hardware components.","baselines":[]},{"id":"SA-10(04)","name":"Trusted Generation","statement":"Require the developer of the system, system component, or system service to employ tools for comparing newly generated versions of security-relevant hardware descriptions, source code, and object code with previous versions.","baselines":[]},{"id":"SA-10(05)","name":"Mapping Integrity for Version Control","statement":"Require the developer of the system, system component, or system service to maintain the integrity of the mapping between the master build data describing the current version of security-relevant hardware, software, and firmware and the on-site master copy of the data for the current version.","baselines":[]},{"id":"SA-10(06)","name":"Trusted Distribution","statement":"Require the developer of the system, system component, or system service to execute procedures for ensuring that security-relevant hardware, software, and firmware updates distributed to the organization are exactly as specified by the master copies.","baselines":[]},{"id":"SA-10(07)","name":"Security and Privacy Representatives","statement":"Require [Assignment: organization-defined security and privacy representatives] to be included in the [Assignment: organization-defined configuration change management and control process].","baselines":[]}],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"SA-10","name":"Developer Configuration Management","description":"Require the developer of the system, system component, or system service to:\na. Perform configuration management during system, component, or service [Selection (one or more): design; development; implementation; operation; disposal];\nb. Document, manage, and control the integrity of changes to [Assignment: organization-defined configuration items under configuration management];\nc. Implement only organization-approved changes to the system, component, or service;\nd. Document approved changes to the system, component, or service and the potential security and privacy impacts of such changes; and\ne. Track security flaws and flaw resolution within the system, component, or service and report findings to [Assignment: organization-defined personnel].","discussion":"Organizations consider the quality and completeness of configuration management activities conducted by developers as direct evidence of applying effective security controls. Controls include protecting the master copies of material used to generate security-relevant portions of the system hardware, software, and firmware from unauthorized modification or destruction. Maintaining the integrity of changes to the system, system component, or system service requires strict configuration control throughout the system development life cycle to track authorized changes and prevent unauthorized changes.\n\nThe configuration items that are placed under configuration management include the formal model; the functional, high-level, and low-level design specifications; other design data; implementation documentation; source code and hardware schematics; the current running version of the object code; tools for comparing new versions of security-relevant hardware descriptions and source code with previous versions; and test fixtures and documentation. Depending on the mission and business needs of organizations and the nature of the contractual relationships in place, developers may provide configuration management support during the operations and maintenance stage of the system development life cycle.","related_controls":["CM-02","CM-03","CM-04","CM-07","CM-09","SA-04","SA-05","SA-08","SA-15","SI-02","SR-03","SR-04","SR-05","SR-06"],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"Adds 'disposal' to parameter text selections Adds 'privacy' to control text"}},"compliance_mappings":{"iso_27001_2022":["6.3","A.8.4","A.8.9","A.8.25","A.8.28","A.8.30","A.8.32"],"iso_27002_2022":["8.4","8.25","8.30","8.32"],"cobit_2019":["BAI03","BAI06"],"pci_dss_v4":["6.2","6.5"],"nist_csf_2":["ID.RA-09","PR.PS-06"],"cis_controls_v8":["CIS 2.6","CIS 16","CIS 16.4"],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":["A.6.1.3","A.6.2.3"],"iec_62443":[],"asd_e8":[],"nis2":["Art. 21(2)(e)"],"apra_cps_234":[],"mas_trm":["6"],"pra_op_resilience":["SS1/21-11.1"],"bsi_grundschutz":[],"anssi":["Hygiene.34","Hygiene.36","SecNumCloud.15.4"],"osfi_b13":["B-13.2.3","B-13.3.2"],"finma_circular":["IV.A(36)","IV.A(37)","IV.A(38)","IV.A(39)"],"gdpr":["Art.25(1)","Art.32(1)(d)"],"dora":["Art.8(5)","Art.9(4)(e)"],"bio2":["8.4","8.25","8.30","8.32"],"rbi_csf":["Annex1.6","ITGRCA.13"],"fisc":["FISC.O3","FISC.O10","FISC.T6"],"lgpd_bcb":[],"hkma_tme1":["TME1.3.2","TME1.4.3"],"mlps_2":["8.1.9.5"],"dnb_good_practice":["DNB.10.1","DNB.10.5"],"cra":["CRA.I.1","CRA.I.2f"],"swift_cscf":[],"cbb_tm":["TM-7"],"cbuae":["CR-6"],"nca_ecc":["1-6","2-3"],"qatar_nia":["SD"],"sama_csf":["3.2"],"uae_ia":["T10"],"bog_cisd":["CISD-SDLC"],"bom_ctrm":["3.6","3.11"],"cbe_csf":["CTO-4","CTO-12"],"sa_js2":["JS2-SA"],"bcbs_239":["Principle 3"],"bot_cyber":["Ch2.5"],"eba_ict":["3.6.2","3.6.3"],"ffiec_is":["II.C.10","II.C.17"],"iosco_cyber":["PROT-6"],"sebi_cscrf":["PR.AS","PR.IP"],"cmmc_2":["CM"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":["B","F"],"fips_140":["FIPS 140-3 §7.5","FIPS 140-3 §7.11"],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":["CC Part 3 — SAR"],"isae_3402":["Clause 4"],"fca_sysc_13":["SYSC 13.7.1","SYSC 13.7.4"],"fda_21_cfr_11":["§11.10(a)"],"fda_cyber":["524B-1","PU-1","SA-3","SBOM-1","SBOM-2"],"hitrust_csf":["09.a","10.d"],"iso_27799":["14.2"],"lloyds_ms":["MS8.4"],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":["P3.1","P3.3","P3.4"],"solvency_ii":["EIOPA-ICT-4.11"],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":["SCO60.52"],"bssc":["NOS-02","TIS-08"],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1072","name":"Software Deployment Tools","tactics":["execution","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Developer configuration management ensures software deployment tools are developed with security controls, change tracking, and vulnerability management that prevent adversary exploitation of deployment infrastructure."},{"id":"T1078","name":"Valid Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Configuration management during development ensures default credentials are changed, test accounts are removed, and secure authentication is implemented before production deployment, eliminating default access vectors."},{"id":"T1495","name":"Firmware Corruption","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Developer configuration management with firmware integrity controls ensures that only authorized, tracked changes reach firmware images, preventing introduction of corrupting modifications during development."},{"id":"T1505","name":"Server Software Component","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Configuration management for server software components tracks all modules, extensions, and plugins through the development lifecycle, detecting unauthorized introduction of backdoor components."},{"id":"T1542","name":"Pre-OS Boot","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Developer configuration management over boot sequences and pre-OS components ensures firmware and bootloader changes are tracked, authorized, and security-reviewed before deployment."},{"id":"T1553","name":"Subvert Trust Controls","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Configuration management for trust control components, including certificate handling and code signing, ensures that trust verification mechanisms are not weakened during the development lifecycle."},{"id":"T1601","name":"Modify System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Developer configuration management for network device system images ensures that firmware builds are tracked, changes are authorized, and integrity is verified throughout the development pipeline."},{"id":"T1647","name":"Plist File Modification","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Configuration management for plist files during development ensures that property list configurations are tracked and changes are authorized, preventing introduction of malicious configuration modifications."},{"id":"T1078.001","name":"Default Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Developer configuration management mandates removal of default accounts and credentials before release, eliminating factory-set passwords that adversaries exploit for initial access to deployed systems."},{"id":"T1078.003","name":"Local Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Configuration management during development ensures local service and administrative accounts are properly secured with unique credentials, preventing exploitation of development-era default configurations."},{"id":"T1078.004","name":"Cloud Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Developer configuration management for cloud deployments ensures cloud account credentials are properly rotated and test accounts are removed before production, eliminating default cloud access."},{"id":"T1195.001","name":"Compromise Software Dependencies and Development Tools","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Configuration management over the software development pipeline tracks dependencies, build tools, and third-party libraries, detecting supply chain compromises that introduce malicious code through development toolchains."},{"id":"T1195.003","name":"Compromise Hardware Supply Chain","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Developer configuration management for hardware components ensures that supply chain integrity is maintained through component tracking, verification, and authorized vendor management during manufacturing."},{"id":"T1213.003","name":"Code Repositories","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Configuration management for code repositories ensures access controls, branch protections, and audit trails prevent unauthorized access to source code and detect suspicious repository activity."},{"id":"T1505.001","name":"SQL Stored Procedures","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Developer configuration management tracks SQL stored procedures through the development lifecycle, detecting unauthorized introduction of malicious procedures that provide persistent database-level backdoor access."},{"id":"T1505.002","name":"Transport Agent","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Configuration management for mail server components ensures transport agents are tracked, authorized, and security-reviewed before deployment, preventing introduction of malicious email interceptors."},{"id":"T1505.004","name":"IIS Components","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Developer configuration management for IIS components tracks module development, registration, and deployment, detecting unauthorized introduction of malicious ISAPI extensions or managed modules."},{"id":"T1542.001","name":"System Firmware","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Configuration management for system firmware development ensures all firmware changes are tracked, authorized, and integrity-verified, preventing introduction of malicious modifications to BIOS/UEFI images."},{"id":"T1542.003","name":"Bootkit","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Developer configuration management over boot component development ensures bootloader integrity through tracked builds, code signing, and authorization, preventing bootkit introduction during development."},{"id":"T1542.004","name":"ROMMONkit","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Configuration management for ROMMON development ensures all ROM Monitor firmware changes are authorized and tracked, preventing adversary introduction of malicious ROMMON modifications."},{"id":"T1542.005","name":"TFTP Boot","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Developer configuration management for network boot images ensures TFTP-served boot files are integrity-verified and tracked, preventing adversary substitution of malicious boot images."},{"id":"T1553.006","name":"Code Signing Policy Modification","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Configuration management over code signing policy ensures that signing certificates, policies, and verification mechanisms are tracked and authorized changes are documented, preventing policy weakening."},{"id":"T1559.003","name":"XPC Services","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Developer configuration management for XPC services ensures service definitions, entitlements, and communication interfaces are security-reviewed and tracked throughout the macOS development lifecycle."},{"id":"T1564.009","name":"Resource Forking","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Configuration management tracking resource fork content during development detects unauthorized addition of hidden data in macOS resource forks that could conceal malicious payloads."},{"id":"T1574.002","name":"DLL Side-Loading","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Developer configuration management ensures applications load DLLs from expected paths with proper manifests, preventing DLL side-loading vulnerabilities through secure development and build practices."},{"id":"T1601.001","name":"Patch System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Configuration management over system image development ensures that patches to network device firmware are authorized, tracked, and integrity-verified before deployment."},{"id":"T1601.002","name":"Downgrade System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Developer configuration management prevents unauthorized image downgrades by maintaining version control and authorization records for all system image releases deployed to network devices."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: iso_27001_2022 A.8.28, A.8.9 added from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR entry 155), which OSA's mapping now takes as its base. 2026-10-03: nist_csf_2 ID.RA-09 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base. 2026-10-03: baselines LMH to -MH, from NIST SP 800-53B Release 5.2.0.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-008","SP-011","SP-028","SP-038","SP-039","SP-045"]}}