PlumbTrackLive demoGRC Risk System

← control library

Developer Screening SA-21

System and Services Acquisition · High baseline ✗ Not implemented

Status — program-wide

What references this control

No risks name this control in their Framework field yet.

No policies reference it yet.


Link a risk or policy to this control

Attaching adds SA-21 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.

Source: NIST SP 800-53 Rev.5, System and Services Acquisition family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.

Control guide — plain-English, per NIST SP 800-53

SA-21 (Developer Screening) requires that the people who build your system — its software, components, and services — are vetted to a trust level that matches the people who run it. It targets outside or contract developers; screening your own employees falls under PS-3 (Personnel Screening). You define two things: the access authorizations a developer needs to do the work, and the extra screening criteria — background checks, citizenship, clearances — they must satisfy first. It is a System and Services Acquisition control that appears at the High baseline, for systems where a compromised developer would do real damage.

What good looks like

Framework mapping

How to move it toward Implemented