System and Services Acquisition Plan
Documents how the system is acquired, developed, documented, engineered, and maintained across the SDLC. Covers resource allocation, acquisition contract language, security-engineering principles, external system services, developer configuration management, developer testing, development process / tooling / standards, system documentation, and the lifecycle treatment of unsupported components. Covers the controls of the SA family in NIST SP 800-53 r5 and aligns with NIST SP 800-160 v1 r1 (Engineering Trustworthy Secure Systems), NIST SP 800-218 (Secure Software Development Framework — SSDF), NIST SP 800-64 r2 (SDLC integration — withdrawn but historically informative), NIST SP 800-161 r1 (SCRM), EO 14028, and OMB M-22-18.