STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← All Controls

SA-22

System and Services AcquisitionRev 5organization

Unsupported System Components

Baselines:LowModerateHigh

Control Statement

a. Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer; or b. Provide the following options for alternative sources for continued support for unsupported components [Selection: organization-defined value].

Supplemental Guidance

Support for system components includes software patches, firmware updates, replacement parts, and maintenance contracts. An example of unsupported components includes when vendors no longer provide critical software patches or product updates, which can result in an opportunity for adversaries to exploit weaknesses in the installed components. Exceptions to replacing unsupported system components include systems that provide critical mission or business capabilities where newer technologies are not available or where the systems are so isolated that installing replacement components is not an option. Alternative sources for support address the need to provide continued support for system components that are no longer supported by the original manufacturers, developers, or vendors when such components remain essential to organizational mission and business functions. If necessary, organizations can establish in-house support by developing customized patches for critical software components or, alternatively, obtain the services of external providers who provide ongoing support for the designated unsupported components through contractual relationships. Such contractual relationships can include open-source software value-added vendors. The increased risk of using unsupported system components can be mitigated, for example, by prohibiting the connection of such components to public or uncontrolled networks, or implementing other forms of isolation.

Related Controls (2)

PL-2SA-3

CCI Identifiers (5)

CCI-003372Define the support from external providers to be provided for alternative sources for continued support for unsupported system components.CCI-003373Provide in-house support and/or organization-defined support from external providers for alternative sources for continued support for unsupported components.CCI-003374The organization documents approval for the continued use of unsupported system components required to satisfy mission/business needs.CCI-003375The organization provides justification for the continued use of unsupported system components required to satisfy mission/business needs.CCI-003376Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer.

Linked STIG Checks (40)

Across 38 STIGs. Click to expand.