SA-5 System Acquisition

Information System Documentation

Medium Risk Moderate Low Cost

SA-5 requires obtaining or developing administrator documentation, user documentation, and security/privacy documentation for the system; documenting attempts to obtain unavailable information; distributing documentation to authorized personnel; and protecting documentation from unauthorized disclosure. In healthcare, missing runbooks for EHR break-glass, interface restarts, or BA-hosted consoles lead to unsafe tribal knowledge and audit failures.

Control Objective

Ensure accurate, controlled documentation exists for operating, using, and securing systems that handle ePHI — and that it reaches the right people without leaking architecture to attackers.

Implementation Guidance

  1. Inventory required docs per major ePHI system: admin/ops, end-user, and security/privacy.
  2. Prefer vendor manuals plus organization-specific runbooks (backup restore, account provisioning, incident steps).
  3. Document gaps when vendors withhold details; track compensating knowledge and risk acceptance.
  4. Store docs in an access-controlled repository; mark sensitive architecture diagrams.
  5. Distribute role-based: helpdesk gets provisioning guides; only infra gets network diagrams.
  6. Review docs on major version upgrades and at least annually.
  7. Include privacy notices/procedures where systems collect or disclose PHI to patients or partners.
  8. Link SA-5 artifacts from the PL-2 system plan so assessors can find them.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

New night-shift EHR analyst

Without a provisioning runbook, staff reuse a shared break-glass account. SA-5 admin docs define named account steps and logging expectations.

PACS upgrade changes ports

Vendor release notes exist but local firewall/NAT steps do not. SA-5 update captures the site-specific security configuration before the cutover.

Assessors request encryption admin guidance

Security documentation for the EHR database TDE and key custody is produced from the controlled SA-5 library — not reconstructed from email threads.

Best Practices

  • Separate user, admin, and security doc sets.
  • Org-specific runbooks layered on vendor manuals.
  • Restricted distribution for architecture details.
  • Version docs with system upgrades.
  • Track unavailable vendor documentation formally.
  • Cross-link from PL-2 / knowledge base.

Common Gaps & Violations

  • Only marketing PDFs; no ops runbooks.
  • Diagrams on open SharePoint sites.
  • Docs never updated after cloud migration.
  • Security config known by one engineer only.
  • No record when vendor refuses design detail.

Required Documentation

  • System documentation standard (SA-5)
  • Admin / user / security doc inventory per system
  • Access-controlled document repository evidence
  • Distribution lists / permissions
  • Gap logs for unavailable vendor information

How to Test & Validate

  1. Select a major ePHI system; confirm all three doc categories exist or gaps are logged.
  2. Verify repository permissions match need-to-know.
  3. Check last update vs last major release.
  4. Interview an admin: can they locate the restore runbook?
  5. Confirm sensitive diagrams are not world-readable.

Audit Considerations

Documentation gaps often surface during contingency and access-control testing. Assessors expect findable admin and security docs, not oral history about how ePHI systems are run.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.316 Policies and procedures — implement and maintain documentation of policies, procedures, and records.
  • 164.308(a)(7) Contingency Plan — recovery procedures depend on accurate system documentation.
  • 164.312 Technical safeguards — configuration of access, audit, integrity, and transmission controls should be documented.
  • 164.530(j) Documentation — privacy documentation retention and availability expectations parallel SA-5 discipline.

Compliance Tips

  • Make doc updates a required exit criterion for CM-3 major changes.
  • Keep a one-page index of where each system’s SA-5 docs live.
  • Redact ePHI examples from screenshots in user guides.

Frequently Asked Questions

Are vendor manuals enough for SA-5?

They help, but you still need organization-specific procedures (accounts, network, backup, incident) that reflect your environment.

Should security documentation be widely published?

No. Distribute to authorized personnel and protect details that would aid an attacker while still meeting operational need.

What if a SaaS vendor will not share internals?

Document the request, what was provided (e.g., SOC 2, admin portals), and residual risk — SA-5 explicitly contemplates unavailable information.

References & Resources

  • NIST SP 800-53 Rev. 5 — SA-5
  • Related controls: PL-2, CM-3, CP-2, SA-4, IR-8

Need Help Implementing SA-5?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.