Skip to main content

πŸ’Ό SA-15 Development Process, Standards, and Tools (M)(H)

  • Contextual name: πŸ’Ό SA-15 Development Process, Standards, and Tools (M)(H)
  • ID: /frameworks/fedramp-moderate-security-controls/sa/15
  • Located in: πŸ’Ό System and Services Acquisition

Description​

a. Require the developer of the system, system component, or system service to follow a documented development process that:

  1. Explicitly addresses security and privacy requirements;

  2. Identifies the standards and tools used in the development process;

  3. Documents the specific tool options and tool configurations used in the development process; and

  4. Documents, manages, and ensures the integrity of changes to the process and/or tools used in development; and

b. Review the development process, standards, tools, tool options, and tool configurations [FedRAMP Assignment: frequency at least annually] to determine if the process, standards, tools, tool options and tool configurations selected and employed can satisfy the following security and privacy requirements: [FedRAMP Assignment: FedRAMP Security Authorization requirements].

Similar​

  • Sections
    • /frameworks/fedramp-high-security-controls/sa/15/03
  • Internal
    • ID: dec-c-1590f8ea

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό FedRAMP High Security Controls β†’ πŸ’Ό SA-15(3) Criticality Analysis (M)(H)

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό SA-15(3) Criticality Analysis (M)(H)