{"data":{"id":"SA-02","name":"Allocation of Resources","family":"SA","family_name":"System and Services Acquisition","withdrawn":false,"description":"a. Determine the high-level information security and privacy requirements for the system or system service in mission and business process planning;\nb. Determine, document, and allocate the resources required to protect the system or system service as part of the organizational capital planning and investment control process; and\nc. Establish a discrete line item for information security and privacy in organizational programming and budgeting documentation.","supplemental_guidance":"Resource allocation for information security and privacy includes funding for system and services acquisition, sustainment, and supply chain-related risks throughout the system development life cycle.","enhancements":[],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"SA-02","name":"Allocation of Resources","description":"a. Determine the high-level information security and privacy requirements for the system or system service in mission and business process planning;\nb. Determine, document, and allocate the resources required to protect the system or system service as part of the organizational capital planning and investment control process; and\nc. Establish a discrete line item for information security and privacy in organizational programming and budgeting documentation.","discussion":"Resource allocation for information security and privacy includes funding for system and services acquisition, sustainment, and supply chain-related risks throughout the system development life cycle.","related_controls":["PL-07","PM-03","PM-11","SA-09","SR-03","SR-05"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":true,"new_in_rev5":false,"changes_from_rev4":"Control text adds reference to privacy Discussion adds reference to supply chain-related risks"}},"compliance_mappings":{"iso_27001_2022":["7.1"],"iso_27002_2022":[],"cobit_2019":[],"pci_dss_v4":[],"nist_csf_2":["GV.RR-03"],"cis_controls_v8":[],"soc2_tsc":["CC1.4","CC4.1"],"finos_ccc":[],"iso_42001_2023":["A.4.5"],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":["Hygiene.36","SecNumCloud.15.1"],"osfi_b13":["B-13.1.2"],"finma_circular":["IV.A(23)","IV.A(24)","IV.A(25)"],"gdpr":["Art.25(1)","Art.32(1)"],"dora":["Art.6(1)"],"bio2":[],"rbi_csf":["ITGRCA.11"],"fisc":["FISC.T1"],"lgpd_bcb":[],"hkma_tme1":["TME1.2.2","TME1.5.3"],"mlps_2":[],"dnb_good_practice":["DNB.1.1"],"cra":["CRA.I.1"],"swift_cscf":[],"cbb_tm":["TM-5"],"nca_ecc":["1-6"],"qatar_nia":["GV","SD"],"uae_ia":["T10"],"bog_cisd":["CISD-SDLC"],"bom_ctrm":["1.3","3.7"],"cpmi_pfmi":["PFMI.P15"],"eba_ict":["3.2.2","3.6.1"],"ffiec_is":["I.C"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":["10.a"],"iso_27799":[],"lloyds_ms":["MS8.1"],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":["EIOPA-ICT-4.1"],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":["Art.34(5)","Art.35(1)","Art.41(1)","Art.54(1)","Art.62(1)"],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[],"metadata":{"last_reviewed":"2026-02-19","review_notes":"","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-001","SP-002","SP-011","SP-018"]}}