Policy and Procedures SA-1
System and Services Acquisition · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds SA-1 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, System and Services Acquisition family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
SA-1 (Policy and Procedures) is the paperwork foundation for the whole System and Services Acquisition family. It asks you to write down — and keep current — a policy for how your organization buys, builds, and brings in systems and software, plus the procedures that put that policy into practice. It is a Low-baseline control, and every other SA control leans on it.
What good looks like
- Write the policy so it covers purpose, scope, roles, responsibilities, management commitment, and how teams coordinate — and make sure it lines up with any laws or regulations you answer to.
- Name an owner. Designate one official responsible for developing, publishing, and maintaining the acquisition policy and its procedures.
- Write the procedures that turn the policy into day-to-day steps — how software and systems actually get requested, approved, and brought onto the server.
- Disseminate both the policy and procedures to the people who need them, not just file them away.
- Review on a schedule and after big changes (a breach, a re-org, a new regulation), then update and re-publish so the documents never go stale.
Framework mapping
- NIST CSF 2.0 — GV.PO-01 — Policy for managing cybersecurity risks is established and communicated
How to move it toward Implemented
- Draft a one- to two-page System and Services Acquisition policy for the lab server: what it covers, who owns it, who approves new software or systems, and a review cadence (for example, yearly).
- Write a short procedures companion — the actual steps to request, approve, and record any new package, service, or system added to the box.
- Save both as dated files (for example,
/etc/plumbtrack/policies/sa-1-acquisition-policy.md) and record the owner’s name and the next review date at the top. - Attach that policy-and-procedures document as hardening evidence on the asset, naming
SA-1in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.