STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← All Controls

SA-10

System and Services AcquisitionRev 5organization

Developer Configuration Management

Baselines:ModerateHigh

Control Statement

Require the developer of the system, system component, or system service to:

Supplemental Guidance

Organizations consider the quality and completeness of configuration management activities conducted by developers as direct evidence of applying effective security controls. Controls include protecting the master copies of material used to generate security-relevant portions of the system hardware, software, and firmware from unauthorized modification or destruction. Maintaining the integrity of changes to the system, system component, or system service requires strict configuration control throughout the system development life cycle to track authorized changes and prevent unauthorized changes. The configuration items that are placed under configuration management include the formal model; the functional, high-level, and low-level design specifications; other design data; implementation documentation; source code and hardware schematics; the current running version of the object code; tools for comparing new versions of security-relevant hardware descriptions and source code with previous versions; and test fixtures and documentation. Depending on the mission and business needs of organizations and the nature of the contractual relationships in place, developers may provide configuration management support during the operations and maintenance stage of the system development life cycle.

Related Controls (14)

CM-2CM-3CM-4CM-7CM-9SA-4SA-5SA-8SA-15SI-2SR-3SR-4SR-5SR-6

CCI Identifiers (33)

CCI-000682The organization requires information system developers to perform configuration management during information system design.CCI-000693The organization requires information system integrators to implement only organization-approved changes.CCI-000697The organization requires information system integrators to track security flaws and flaw resolution.CCI-000683The organization requires information system developers to perform configuration management during information system development.CCI-000686The organization requires information system integrators to perform configuration management during information system design.CCI-000690The organization requires information system developers to manage and control changes to the information system during design.CCI-000691The organization requires information system integrators to manage and control changes to the information system during design.CCI-000692Require the developer of the system, system component, or system service to implement only organization-approved changes to the system, component, or service.

Linked STIG Checks (1)

Across 1 STIGs. Click to expand.

CCI-000696The organization requires that information system developers track security flaws and flaw resolution.
CCI-001654The organization requires the information system developers to manage and control changes to the information system during modification.
CCI-000687The organization requires information system integrators to perform configuration management during information system development.
CCI-000688The organization requires information system integrators to perform configuration management during information system implementation.
CCI-000689The organization requires information system integrators to perform configuration management during information system operation.
CCI-000694Require the developer of the system, system component, or system service to document approved changes to the system, component, or service.
CCI-000695The organization requires information system integrators to document approved changes to the information system.
CCI-003160Require the developer of the system, system component, or system service to document the potential security impacts of approved changes to the system, component, or service.
CCI-003161Require the developer of the system, system component, or system service to track security flaws within the system, component, or service.
CCI-003162Require the developer of the system, system component, or system service to track flaw resolution within the system, component, or service.
CCI-003163Require the developer of the system, system component, or system service to report findings of security flaws and flaw resolution within the system, component, or service to organization-defined personnel.
CCI-001655The organization requires the information system integrators to manage and control changes to the information system during modification.
CCI-000684The organization requires information system developers to perform configuration management during information system implementation.
CCI-000685The organization requires information system developers to perform configuration management during information system operation.
CCI-004794Require the developer of the system, system component, or system service to document the potential privacy impacts of approved changes to the system, component, or service.
CCI-001650The organization requires the information system developers to manage and control changes to the information system during development.
CCI-001651The organization requires the information system integrators to manage and control changes to the information system during development.
CCI-001652The organization requires the information system developers to manage and control changes to the information system during implementation.
CCI-001653The organization requires the information system integrators to manage and control changes to the information system during implementation.
CCI-003164Defines the personnel to whom security flaw findings and flaw resolution within the system, component, or service are reported.
CCI-003155Require the developer of the system, system component, or system service to perform configuration management during system, component, or service design, development, implementation, operation and/or disposal.
CCI-003156Require the developer of the system, system component, or system service to document the integrity of changes to organization-defined configuration items under configuration management.
CCI-003157Require the developer of the system, system component, or system service to manage the integrity of changes to organization-defined configuration items under configuration management.
CCI-003158Require the developer of the system, system component, or system service to control the integrity of changes to organization-defined configuration items under configuration management.
CCI-003159Defines the configuration items under configuration management that require the integrity of changes to be documented, managed and controlled.