NIST SP 800-53: what it asks of unsupported software
SA-22 asks that system components are replaced when support is no longer available from the developer, vendor or manufacturer, or that alternative sources of continued support are provided. CM-8 asks for an accurate component inventory; SI-2 asks that security-relevant updates are installed within an organisation-defined period.
- Scheme
- NIST SP 800-53 Rev 5
- When it is placed
- Placed when you say NIST SP 800-53 is your control set.
- Held text
- NIST SP 800-53 Rev 5 on the standards site, read 30 Sep 2026
Findings that cite it
9 of 10- 1 Past vendor security support, still installed
- 2 Extended or paid support only
- 3 Ends before your next assessment
- 4 Ends within the window you set
- 6 One product at several versions, the oldest unsupported
- 7 Not in the lifecycle record
- 8 Unsupported with no owner
- 9 Unsupported with no exception recorded
- 10 Evergreen product behind the current release
The clauses cited
3 clausesNIST SP 800-53 CM-8System Component InventoryCM-8 System Component Inventory. a. Develop and document an inventory of system components that: 1. Accurately reflects the system; 2. Includes all components within the system; 3. Does not include duplicate accounting of components or components assigned to any other system; 4. Is at the level of granularity deemed necessary for tracking and reporting; and 5. Includes the following information to achieve system component accountability: [Assignment: organization-defined information deemed necessary to achieve effective system component accountability]; and b. Review and update the system component inventory [Assignment: organization-defined frequency].
NIST SP 800-53 SA-22Unsupported System ComponentsSA-22 Unsupported System Components. a. Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer; or b. Provide the following options for alternative sources for continued support for unsupported components [Selection (one or more): in-house support; [Assignment: organization-defined support from external providers]].
NIST SP 800-53 SI-2Flaw RemediationSI-2 Flaw Remediation. a. Identify, report, and correct system flaws; b. Test software and firmware updates related to flaw remediation for effectiveness and potential side effects before installation; c. Install security-relevant software and firmware updates within [Assignment: organization-defined time period] of the release of the updates; and d. Incorporate flaw remediation into the organizational configuration management process.