NIST 800-53 REV 5 • SYSTEM AND SERVICES ACQUISITION

SA-12(9)Operations Security

CMMC Practice Mapping

No direct CMMC mapping

NIST 800-171 Mapping

No direct NIST 800-171 mapping

Related Controls

No related controls listed

Practitioner Notes

Apply operations security (OPSEC) to your supply chain processes. Information about your security infrastructure, deployment schedules, and vendor relationships should not be publicly available.

Example 1: Do not publicly disclose specific security products and versions in use (e.g., on job postings, social media, or website metadata). Attackers use this information to tailor their attacks to your specific technology stack. Keep infrastructure details internal.

Example 2: When communicating with vendors about security requirements, use secure channels (encrypted email, secure portals) rather than standard email. Sensitive procurement details, security architecture information, and vulnerability data should never travel over unprotected channels.