STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← All Controls

SA-15 (5)

System and Services AcquisitionRev 5organization

Development Process, Standards, and Tools

Control Statement

Require the developer of the system, system component, or system service to reduce attack surfaces to [Assignment: thresholds].

Supplemental Guidance

Attack surface reduction is closely aligned with threat and vulnerability analyses and system architecture and design. Attack surface reduction is a means of reducing risk to organizations by giving attackers less opportunity to exploit weaknesses or deficiencies (i.e., potential vulnerabilities) within systems, system components, and system services. Attack surface reduction includes implementing the concept of layered defenses, applying the principles of least privilege and least functionality, applying secure software development practices, deprecating unsafe functions, reducing entry points available to unauthorized users, reducing the amount of code that executes, and eliminating application programming interfaces (APIs) that are vulnerable to attacks.

Related Controls (4)

AC-6CM-7RA-3SA-11

CCI Identifiers (2)

CCI-003272Require the developer of the system, system component, or system service to reduce attack surfaces to organization-defined thresholds.CCI-003273Defines the thresholds to which the developer of the system, system component, or system service is required to reduce attack surfaces.

Linked STIG Checks (1)

Across 1 STIGs. Click to expand.