| SA-8(13) | System and Services Acquisition | Minimized Security Elements |
| SA-8(14) | System and Services Acquisition | Least Privilege |
| SA-8(15) | System and Services Acquisition | Predicate Permission |
| SA-8(16) | System and Services Acquisition | Self-reliant Trustworthiness |
| SA-8(17) | System and Services Acquisition | Secure Distributed Composition |
| SA-8(18) | System and Services Acquisition | Trusted Communications Channels |
| SA-8(19) | System and Services Acquisition | Continuous Protection |
| SA-8(2) | System and Services Acquisition | Least Common Mechanism |
| SA-8(20) | System and Services Acquisition | Secure Metadata Management |
| SA-8(21) | System and Services Acquisition | Self-analysis |
| SA-8(22) | System and Services Acquisition | Accountability and Traceability |
| SA-8(23) | System and Services Acquisition | Secure Defaults |
| SA-8(24) | System and Services Acquisition | Secure Failure and Recovery |
| SA-8(25) | System and Services Acquisition | Economic Security |
| SA-8(26) | System and Services Acquisition | Performance Security |
| SA-8(27) | System and Services Acquisition | Human Factored Security |
| SA-8(28) | System and Services Acquisition | Acceptable Security |
| SA-8(29) | System and Services Acquisition | Repeatable and Documented Procedures |
| SA-8(3) | System and Services Acquisition | Modularity and Layering |
| SA-8(30) | System and Services Acquisition | Procedural Rigor |
| SA-8(31) | System and Services Acquisition | Secure System Modification |
| SA-8(32) | System and Services Acquisition | Sufficient Documentation |
| SA-8(33) | System and Services Acquisition | Minimization |
| SA-8(4) | System and Services Acquisition | Partially Ordered Dependencies |
| SA-8(5) | System and Services Acquisition | Efficiently Mediated Access |
| SA-8(6) | System and Services Acquisition | Minimized Sharing |
| SA-8(7) | System and Services Acquisition | Reduced Complexity |
| SA-8(8) | System and Services Acquisition | Secure Evolvability |
| SA-8(9) | System and Services Acquisition | Trusted Components |
| SA-9 | System and Services Acquisition | External System Services |
| SA-9(1) | System and Services Acquisition | Risk Assessments and Organizational Approvals |
| SA-9(2) | System and Services Acquisition | Identification of Functions, Ports, Protocols, and Services |
| SA-9(3) | System and Services Acquisition | Establish and Maintain Trust Relationship with Providers |
| SA-9(4) | System and Services Acquisition | Consistent Interests of Consumers and Providers |
| SA-9(5) | System and Services Acquisition | Processing, Storage, and Service Location |
| SA-9(6) | System and Services Acquisition | Organization-controlled Cryptographic Keys |
| SA-9(7) | System and Services Acquisition | Organization-controlled Integrity Checking |
| SA-9(8) | System and Services Acquisition | Processing and Storage Location — U.S. Jurisdiction |
| SC-1 | System and Communications Protection | Policy and Procedures |
| SC-10 | System and Communications Protection | Network Disconnect |
| SC-11 | System and Communications Protection | Trusted Path |
| SC-11(1) | System and Communications Protection | Irrefutable Communications Path |
| SC-12 | System and Communications Protection | Cryptographic Key Establishment and Management |
| SC-12(1) | System and Communications Protection | Availability |
| SC-12(2) | System and Communications Protection | Symmetric Keys |
| SC-12(3) | System and Communications Protection | Asymmetric Keys |
| SC-12(4) | System and Communications Protection | PKI Certificates |
| SC-12(5) | System and Communications Protection | PKI Certificates / Hardware Tokens |
| SC-12(6) | System and Communications Protection | Physical Control of Keys |
| SC-13 | System and Communications Protection | Cryptographic Protection |