{"data":{"id":"SA-22","name":"Unsupported System Components","family":"SA","family_name":"System and Services Acquisition","withdrawn":false,"description":"a. Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer; or\nb. Provide the following options for alternative sources for continued support for unsupported components [Selection (one or more): in-house support; [Assignment: organization-defined support from external providers]].","supplemental_guidance":"Support for system components includes software patches, firmware updates, replacement parts, and maintenance contracts. An example of unsupported components includes when vendors no longer provide critical software patches or product updates, which can result in an opportunity for adversaries to exploit weaknesses in the installed components. Exceptions to replacing unsupported system components include systems that provide critical mission or business capabilities where newer technologies are not available or where the systems are so isolated that installing replacement components is not an option.\n\nAlternative sources for support address the need to provide continued support for system components that are no longer supported by the original manufacturers, developers, or vendors when such components remain essential to organizational mission and business functions. If necessary, organizations can establish in-house support by developing customized patches for critical software components or, alternatively, obtain the services of external providers who provide ongoing support for the designated unsupported components through contractual relationships. Such contractual relationships can include open-source software value-added vendors. The increased risk of using unsupported system components can be mitigated, for example, by prohibiting the connection of such components to public or uncontrolled networks, or implementing other forms of isolation.","enhancements":[{"id":"SA-22(01)","name":"Alternative Sources for Continued Support","withdrawn":true,"incorporated_into":["SA-22"]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"SA-22","name":"Unsupported System Components","description":"a. Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer; or\nb. Provide the following options for alternative sources for continued support for unsupported components [Selection (one or more): in-house support; [Assignment: organization-defined support from external providers]].","discussion":"Support for system components includes software patches, firmware updates, replacement parts, and maintenance contracts. An example of unsupported components includes when vendors no longer provide critical software patches or product updates, which can result in an opportunity for adversaries to exploit weaknesses in the installed components. Exceptions to replacing unsupported system components include systems that provide critical mission or business capabilities where newer technologies are not available or where the systems are so isolated that installing replacement components is not an option.\n\nAlternative sources for support address the need to provide continued support for system components that are no longer supported by the original manufacturers, developers, or vendors when such components remain essential to organizational mission and business functions. If necessary, organizations can establish in-house support by developing customized patches for critical software components or, alternatively, obtain the services of external providers who provide ongoing support for the designated unsupported components through contractual relationships. Such contractual relationships can include open-source software value-added vendors. The increased risk of using unsupported system components can be mitigated, for example, by prohibiting the connection of such components to public or uncontrolled networks, or implementing other forms of isolation.","related_controls":["PL-02","SA-03"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":""}},"compliance_mappings":{"iso_27001_2022":["A.8.19"],"iso_27002_2022":["8.19"],"cobit_2019":["BAI09"],"pci_dss_v4":[],"nist_csf_2":["ID.AM-08","PR.PS-02","PR.PS-03"],"cis_controls_v8":["CIS 2","CIS 2.2","CIS 9.1","CIS 12.1","CIS 16.5"],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":["E8-6","E8-6 ML3"],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":[],"osfi_b13":[],"finma_circular":[],"gdpr":[],"dora":["Art.8(5)"],"bio2":["8.19"],"rbi_csf":["Annex1.2","Annex1.7"],"fisc":[],"lgpd_bcb":[],"hkma_tme1":["TME1.3.4"],"mlps_2":[],"dnb_good_practice":["DNB.19.3"],"cra":["CRA.I.2c","CRA.II.2","CRA.Info.7"],"swift_cscf":["SWIFT.2.2"],"cbb_tm":["TM-15"],"cbuae":["CR-12"],"nca_ecc":["2-3","2-10"],"qatar_nia":["SD"],"sama_csf":["3.2","3.5"],"uae_ia":["T10"],"bog_cisd":["CISD-XVI"],"bom_ctrm":["3.7"],"cbe_csf":["CRM-2","CTO-9","OVM-1"],"cbn_csf":["Part2.4"],"sa_js2":["JS2-8.5","JS2-8.7"],"bot_cyber":["Ch2.5"],"eba_ict":["3.5(b)"],"ecb_croe":["CROE.2.3.4","CROE.2.8.2"],"ffiec_is":["II.C.11","II.C.14"],"iosco_cyber":["PROT-7"],"nydfs_500":["500.13"],"sebi_cscrf":["GV.SC"],"nerc_cip":["CIP-013-2"],"nrc_73_54":[],"tsa_psd":["SD-2 Sec D"],"ieee_1686":["5.10"],"ferc_cip":["Order 829"],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":["PU-2","PU-3"],"hitrust_csf":[],"iso_27799":[],"lloyds_ms":[],"naic_ds":["4-asset"],"nhs_dspt":["NDG-8.1"],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":["MASVS-CODE-1","MASVS-CODE-2"],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1189","name":"Drive-by Compromise","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Replacing unsupported system components—including end-of-life browsers, plugins, and operating systems—reduces drive-by compromise risk by eliminating unpatched client-side vulnerabilities that adversaries target through web exploits."},{"id":"T1195","name":"Supply Chain Compromise","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Replacing unsupported components with maintained alternatives reduces supply chain compromise risk by ensuring all system components receive current security updates and vendor-supported integrity verification."},{"id":"T1543","name":"Create or Modify System Process","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Replacing unsupported operating systems and service management frameworks ensures system process creation controls remain effective by maintaining vendor support for security patches and configuration hardening."},{"id":"T1195.001","name":"Compromise Software Dependencies and Development Tools","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Replacing end-of-life development tools and software dependencies with supported alternatives reduces compromise risk by ensuring development toolchains receive security patches for newly discovered vulnerabilities."},{"id":"T1195.002","name":"Compromise Software Supply Chain","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Maintaining supported software versions with active vendor security response ensures that supply chain compromise affecting software distribution channels is promptly patched with vendor-provided remediation."},{"id":"T1543.002","name":"Systemd Service","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Replacing unsupported Linux distributions that no longer receive systemd security patches ensures that systemd service hardening features remain effective against adversary persistence through service creation."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"Generated from NIST SP 800-53 Rev 5 with compliance mappings from framework-coverage data 2026-10-03: baselines --- to LMH; Rev 5 baselines --- to LMH, from NIST SP 800-53B Release 5.2.0.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-050"]}}