FedRAMP Controls / SA

SA-2 Allocation of Resources

Family SA
Baselines moderate
Mapped KSIs 1

Control statement

a. Determine the high-level information security and privacy requirements for the system or system service in mission and business process planning;
    b. Determine, document, and allocate the resources required to protect the system or system service as part of the organizational capital planning and investment control process; and
    c. Establish a discrete line item for information security and privacy in organizational programming and budgeting documentation.

Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is preserved in the catalog database.

Covered by these Key Security Indicators

KSITitleCategory
KSI-PIY-06Security Investment Effectiveness
_Persistently_ review the effectiveness of the organization's investments in achieving security objectives.
Policy and Inventory