CCI-003373
CCI-003373 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if [SA-22_ODP[01]; one or more of the following PARAMETER VALUES is/are selected: {in-house support; [SA-22_ODP[02]; support from external providers is defined (if selected)]}] provide options for alternative sources for continued support for unsupported components.
Validation Procedures
Examine: [SELECT FROM: System and services acquisition policy; procedures addressing the replacement or continued use of unsupported system components; documented evidence of replacing unsupported system components; documented approvals (including justification) for the continued use of unsupported system components; system security plan; supply chain risk management plan; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with system and service acquisition responsibilities; organizational personnel with information security responsibilities; organizational personnel with the responsibility for the system development life cycle; organizational personnel responsible for component replacement]. Test: [SELECT FROM: Organizational processes for replacing unsupported system components; mechanisms supporting and/or implementing the replacement of unsupported system components].