# SA-23 Specialization

NIST SP 800-53 control. Family: SA System and Services Acquisition. Function: preventative. In no baseline. Mapping licence: CC BY-SA 4.0.

Statement: Employ [Selection (one or more): design; modification; augmentation; reconfiguration] on [Assignment: organization-defined systems or system components] supporting mission essential services or functions to increase the trustworthiness in those systems or components.
Guidance: It is often necessary for a system or system component that supports mission-essential services or functions to be enhanced to maximize the trustworthiness of the resource. Sometimes this enhancement is done at the design level. In other instances, it is done post-design, either through modifications of the system in question or by augmenting the system with additional components. For example, supplemental authentication or non-repudiation functions may be added to the system to enhance the identity of critical resources to other resources that depend on the organization-defined resources.

## Clauses by framework (6 frameworks)
- bsi_grundschutz: APP.3.1
- anssi: SecNumCloud.15.3
- osfi_b13: B-13.2.2
- finma_circular: IV.F(100), V(102), V(103)
- rbi_csf: Annex1.6
- fisc: FISC.O6

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/SA-23
- Clauses only: /api/v1/controls/SA-23?fields=mappings
- Page for people: /controls/sa-23/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
