Control Mapping Readerplace a control, see the map

NIST800-SA-4(7) SA-4(7) Acquisition Process | NIAP-approved Protection Profiles

NIST800-SA-4(7) in NIST SP 800-53 Rev 5 (NIST SP 800-53 Rev 5, Release 5.2.0). All NIST SP 800-53 Rev 5 controls held. Open NIST SP 800-53 Rev 5 on the standards site.

The control as we hold it

SA-4(7) Acquisition Process | NIAP-approved Protection Profiles. (a) Limit the use of commercially provided information assurance and information assurance-enabled information technology products to those products that have been successfully evaluated against a National Information Assurance partnership (NIAP)-approved Protection Profile for a specific technology type, if such a profile exists; and (b) Require, if no NIAP-approved Protection Profile exists for a specific technology type but a commercially provided information technology product relies on cryptographic functionality to enforce its security policy, that the cryptographic module is FIPS-validated or NSA-approved.

Reviewed and closest counterparts in the other frameworks

We hold no cross-framework row for NIST800-SA-4(7) yet. The reviewed pairs page lists the released pairs and their coverage.

What an auditor commonly asks for

General guidance for this control area (domain: SA - System and Services Acquisition), in our words, not a statement of the standard and not binding on an assessor.

Buy the reviewed crosswalk pair Place your own control