Skip to main content

💼 SA-17 (1) FORMAL POLICY MODEL

Description​

The organization requires the developer of the information system, system component, or information system service to: SA-17 (1)(a) Produce, as an integral part of the development process, a formal policy model describing the [Assignment: organization-defined elements of organizational security policy] to be enforced; and SA-17 (1)(b) Prove that the formal policy model is internally consistent and sufficient to enforce the defined elements of the organizational security policy when implemented.

Similar​

  • Internal
    • ID: dec-c-0cb779df

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags