Skip to main content

πŸ’Ό SA-15 DEVELOPMENT PROCESS, STANDARDS, AND TOOLS

  • Contextual name: πŸ’Ό SA-15 DEVELOPMENT PROCESS, STANDARDS, AND TOOLS
  • ID: /frameworks/nist-sp-800-53-r4/sa/15
  • Located in: πŸ’Ό SA SYSTEM AND SERVICES ACQUISITION

Description​

The organization: SA-15a. Requires the developer of the information system, system component, or information system service to follow a documented development process that: SA-15a.1. Explicitly addresses security requirements; SA-15a.2. Identifies the standards and tools used in the development process; SA-15a.3. Documents the specific tool options and tool configurations used in the development process; and SA-15a.4. Documents, manages, and ensures the integrity of changes to the process and/or tools used in development; and SA-15b. Reviews the development process, standards, tools, and tool options/configurations [Assignment: organization-defined frequency] to determine if the process, standards, tools, and tool options/configurations selected and employed can satisfy [Assignment: organization-defined security requirements].

Similar​

  • Internal
    • ID: dec-c-fd8dac7b

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό ID.SC-2: Suppliers and third party partners of information systems, components, and services are identified, prioritized, and assessed using a cyber supply chain risk assessment process77
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό PR.IP-2: A System Development Life Cycle to manage systems is implemented66

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό SA-15 (1) QUALITY METRICS
πŸ’Ό SA-15 (2) SECURITY TRACKING TOOLS
πŸ’Ό SA-15 (3) CRITICALITY ANALYSIS
πŸ’Ό SA-15 (4) THREAT MODELING _ VULNERABILITY ANALYSIS
πŸ’Ό SA-15 (5) ATTACK SURFACE REDUCTION
πŸ’Ό SA-15 (6) CONTINUOUS IMPROVEMENT
πŸ’Ό SA-15 (7) AUTOMATED VULNERABILITY ANALYSIS
πŸ’Ό SA-15 (8) REUSE OF THREAT _ VULNERABILITY INFORMATION
πŸ’Ό SA-15 (9) USE OF LIVE DATA
πŸ’Ό SA-15 (10) INCIDENT RESPONSE PLAN
πŸ’Ό SA-15 (11) ARCHIVE INFORMATION SYSTEM _ COMPONENT