Quick-reference card
| Field | Value |
|---|---|
| Control ID | SA-23 |
| Control name | Specialization |
| Framework | NIST SP 800-53 Revision 5 |
| Control family | System and Services Acquisition |
| Baselines | Not assigned to any baseline |
| Relevance | Organization (First Party) |
| Risk severity | Low |
What this control requires
SA-23 requires your organization to strengthen systems that support mission-essential services by applying design modifications, augmentations, or reconfigurations that increase their trustworthiness. Most security programs focus on protecting systems at their perimeter, but SA-23 targets the internal reliability and integrity of the components you depend on most. The control recognizes that not all systems carry equal operational weight, and the ones supporting essential functions deserve more than standard hardening.
In practice, you need to identify which systems or components underpin critical operations and then apply targeted enhancements to make those resources more resilient. These enhancements can take several forms. Design modifications change the architecture of a system before or after deployment. Augmentation adds capabilities, such as supplemental authentication or non-repudiation functions, to reinforce the identity and integrity of critical resources. Reconfiguration adjusts existing settings and parameters to harden a system against misuse or failure.
The intent behind this control is to ensure that the systems your organization relies on for essential functions aren’t running with default trust assumptions. You’re expected to make deliberate, documented decisions about how to increase confidence in those systems. This requirement sits within the broader System and Services Acquisition family, which governs how organizations acquire, develop, and maintain trustworthy systems. SA-23 is one of the more targeted controls in the NIST SP 800-53 framework, applying only when a system’s role in essential operations justifies the additional investment.
Why it matters
Organizations that skip trustworthiness enhancements for mission-essential systems create a gap between how critical a resource is and how hardened it is in practice. SA-23 addresses that gap directly, and failing to implement it leaves your highest-value systems running with the same baseline protections as everything else.
Without deliberate specialization, audit findings can flag your organization for insufficient risk treatment on the systems that matter most. Assessors look for documented evidence that you’ve identified essential services and applied targeted modifications to the components supporting those services.
In practice, a missing or incomplete implementation makes it difficult to demonstrate that your security program accounts for operational criticality. When assessors can’t find documented rationale for why certain systems received specific enhancements, they have no way to verify that your organization made deliberate trustworthiness decisions rather than relying on default configurations.
The consequences extend beyond audit risk. If a mission-essential system fails or is compromised because it lacked appropriate hardening, the operational impact is disproportionate, particularly during high-stakes events like mergers and acquisitions where system integrity is under heightened scrutiny. Organizations looking to reduce the likelihood of third-party breaches should consider SA-23 as part of a broader strategy for hardening the systems their partners depend on. These are the systems your organization can’t afford to lose, and SA-23 exists to ensure they receive proportionate protection.
What attackers exploit when trustworthiness enhancements are absent:
- Default configurations on critical infrastructure components that were never hardened post-deployment
- Missing supplemental authentication on resources that other systems depend on for identity verification
- Lack of non-repudiation controls, allowing adversaries to deny or obscure malicious actions within essential services
- Architectural weaknesses in systems that were acquired or built without mission-specific design considerations
- Insufficient integrity verification between interconnected components supporting essential functions
How to implement
For your organization
The biggest challenge with SA-23 isn’t the technical implementation itself. It’s knowing which systems qualify as mission-essential and then choosing the right enhancement approach for each one.
Step 1: Identify mission-essential systems and components
Start by working with your business continuity and operations teams to catalog the systems and components that support mission-essential services or functions. This identification should build directly on the output of your criticality analysis process. Document why each system qualifies and what services depend on it.
Step 2: Select the appropriate enhancement approach
For each identified system, determine whether design modification, augmentation, or reconfiguration is the right fit. Design modification works best during system acquisition or major upgrades when you can change the underlying architecture. Augmentation is appropriate when you need to add new security functions, such as supplemental authentication mechanisms or non-repudiation capabilities, to an existing system. Reconfiguration applies when the system already has underused security features that can be activated or tightened.
Step 3: Document and implement the enhancements
Create an implementation plan for each system that specifies what enhancement you’re applying, the rationale for choosing that approach, and the expected improvement in trustworthiness. Your attack surface management program should track these changes as part of your broader visibility into system configurations.
Step 4: Integrate with your supply chain risk management plan
Record all specialization decisions in your supply chain risk management plan and system security plan, particularly when working with external providers whose risk posture you track through a vendor risk management platform. Assessors need to see a clear thread from criticality determination through enhancement selection to implemented controls. This documentation should include the justification for each approach chosen and the specific mission-essential function the target system supports.
Step 5: Validate and maintain
Test that the enhancements work as intended. Verify that supplemental authentication functions correctly, that design modifications don’t introduce new dependencies, and that reconfigurations don’t break interoperability with dependent systems. Establish a review cycle to reassess whether your enhancements remain appropriate as mission needs evolve.
Common mistakes to avoid:
- Treating all systems equally rather than applying enhancements proportional to criticality
- Choosing augmentation when reconfiguration of existing features would achieve the same outcome with less complexity
- Failing to document the rationale behind each enhancement decision, leaving assessors without evidence of deliberate analysis
- Implementing enhancements without coordinating with the teams responsible for dependent services
Evidence examples
| Evidence Type | Example Artifact |
|---|---|
| Policy documentation | System and services acquisition policy defining when design modification, augmentation, or reconfiguration is required for mission-essential components |
| Criticality determination records | Documented analysis identifying which systems and components support mission-essential services or functions |
| Enhancement implementation plans | Procedures describing the specific design modification, augmentation, or reconfiguration applied to each identified system |
| System security plan entries | System security plan sections documenting trustworthiness enhancements and their alignment with mission requirements |
| Supply chain risk management plan | Supply chain risk management plan entries linking specialization decisions to acquisition and lifecycle controls |
| Validation and testing records | Test results confirming that implemented enhancements, such as supplemental authentication or non-repudiation functions, operate as intended |
Cross-framework mapping
No cross-framework mappings are currently configured for SA-23.
Related controls
- RA-09 — Criticality Analysis: Identifies mission-essential systems that SA-23 targets for trustworthiness enhancements.
- SA-08 — Security and Privacy Engineering Principles: Provides the engineering design principles that inform how SA-23 modifications should be architected.
Frequently asked questions
What is NIST SP 800-53 SA-23?
SA-23 requires organizations to increase the trustworthiness of systems supporting mission-essential services by applying design modifications, augmentations, or reconfigurations. The control focuses on ensuring that your most critical systems receive targeted enhancements rather than relying on baseline security measures. You choose from three approaches based on what fits the system: modifying its design, adding new security functions like supplemental authentication, or reconfiguring existing capabilities to improve resilience. SA-23 isn’t assigned to any baseline, which means it applies selectively to organizations whose risk profile warrants additional hardening of essential systems.
What happens if SA-23 is not implemented?
Without SA-23, your mission-essential systems operate at the same trust level as non-critical infrastructure, leaving your highest-value services without proportionate protection. Assessors reviewing your system and services acquisition controls will flag the absence of documented trustworthiness enhancements for critical components. The operational risk is that a compromise or failure in an un-hardened essential system causes disproportionate impact because no design modification, augmentation, or reconfiguration was applied to increase its resilience.
How do you audit SA-23?
Auditing SA-23 starts with verifying that your organization has identified which systems support mission-essential services and documented the specific enhancement applied to each one. Assessors look for evidence that design modification, augmentation, or reconfiguration was deliberately selected and implemented, not just planned. They’ll review your system security plan, supply chain risk management plan, and any validation records confirming that enhancements like supplemental authentication or non-repudiation functions are operating as intended. Expect assessors to trace the decision chain from criticality determination through enhancement selection to test results showing the modification works.
What is the difference between design modification, augmentation, and reconfiguration in SA-23?
Design modification changes the architecture of a system or component to build in trustworthiness from the ground up, typically during acquisition or a major upgrade. Augmentation adds new security capabilities to an existing system, such as supplemental authentication or non-repudiation functions, that weren’t part of the original design. Reconfiguration adjusts the settings, parameters, or enabled features of a current system to strengthen its security posture without changing its architecture or adding new components.