NIST 800-53 REV 5 • SYSTEM AND SERVICES ACQUISITION
SA-12(9) — Operations Security
CMMC Practice Mapping
No direct CMMC mapping
NIST 800-171 Mapping
No direct NIST 800-171 mapping
Related Controls
No related controls listed
Practitioner Notes
Apply operations security (OPSEC) to your supply chain processes. Information about your security infrastructure, deployment schedules, and vendor relationships should not be publicly available.
Example 1: Do not publicly disclose specific security products and versions in use (e.g., on job postings, social media, or website metadata). Attackers use this information to tailor their attacks to your specific technology stack. Keep infrastructure details internal.
Example 2: When communicating with vendors about security requirements, use secure channels (encrypted email, secure portals) rather than standard email. Sensitive procurement details, security architecture information, and vulnerability data should never travel over unprotected channels.