πΌ SA-11 DEVELOPER SECURITY TESTING AND EVALUATION
- Contextual name: πΌ SA-11 DEVELOPER SECURITY TESTING AND EVALUATION
- ID:
/frameworks/nist-sp-800-53-r4/sa/11
- Located in: πΌ SA SYSTEM AND SERVICES ACQUISITION
Descriptionβ
The organization requires the developer of the information system, system component, or information system service to: SA-11a. Create and implement a security assessment plan; SA-11b. Perform [Selection (one or more): unit; integration; system; regression] testing/evaluation at [Assignment: organization-defined depth and coverage]; SA-11c. Produce evidence of the execution of the security assessment plan and the results of the security testing/evaluation; SA-11d. Implement a verifiable flaw remediation process; and SA-11e. Correct flaws identified during security testing/evaluation.
Similarβ
- Internal
- ID:
dec-c-9ddee91f
- ID:
Similar Sections (Give Policies To)β
Sub Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ SA-11 (1) STATIC CODE ANALYSIS | ||||
πΌ SA-11 (2) THREAT AND VULNERABILITY ANALYSES | ||||
πΌ SA-11 (3) INDEPENDENT VERIFICATION OF ASSESSMENT PLANS _ EVIDENCE | ||||
πΌ SA-11 (4) MANUAL CODE REVIEWS | ||||
πΌ SA-11 (5) PENETRATION TESTING | ||||
πΌ SA-11 (6) ATTACK SURFACE REVIEWS | ||||
πΌ SA-11 (7) VERIFY SCOPE OF TESTING _ EVALUATION | ||||
πΌ SA-11 (8) DYNAMIC CODE ANALYSIS |