Skip to main content

💼 SA-15 Development Process, Standards, and Tools

  • ID: /frameworks/nist-sp-800-53-r5/sa/15

Description​

a. Require the developer of the system, system component, or system service to follow a documented development process that:

  1. Explicitly addresses security and privacy requirements;
  2. Identifies the standards and tools used in the development process;
  3. Documents the specific tool options and tool configurations used in the development process; and
  4. Documents, manages, and ensures the integrity of changes to the process and/or tools used in development; and b. Review the development process, standards, tools, tool options, and tool configurations [Assignment: organization-defined frequency] to determine if the process, standards, tools, tool options and tool configurations selected and employed can satisfy the following security and privacy requirements: [Assignment: organization-defined security and privacy requirements].

Similar​

  • Internal
    • ID: dec-c-1590f8ea

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 NIST CSF v2.0 → 💼 ID.RA-09: The authenticity and integrity of hardware and software are assessed prior to acquisition and use4no data

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 SA-15(1) Development Process, Standards, and Tools _ Quality Metricsno data
💼 SA-15(2) Development Process, Standards, and Tools _ Security and Privacy Tracking Tools1no data
💼 SA-15(3) Development Process, Standards, and Tools _ Criticality Analysisno data
💼 SA-15(4) Development Process, Standards, and Tools _ Threat Modeling and Vulnerability Analysisno data
💼 SA-15(5) Development Process, Standards, and Tools _ Attack Surface Reductionno data
💼 SA-15(6) Development Process, Standards, and Tools _ Continuous Improvementno data
💼 SA-15(7) Development Process, Standards, and Tools _ Automated Vulnerability Analysisno data
💼 SA-15(8) Development Process, Standards, and Tools _ Reuse of Threat and Vulnerability Information1no data
💼 SA-15(9) Development Process, Standards, and Tools _ Use of Live Datano data
💼 SA-15(10) Development Process, Standards, and Tools _ Incident Response Planno data
💼 SA-15(11) Development Process, Standards, and Tools _ Archive System or Componentno data
💼 SA-15(12) Development Process, Standards, and Tools _ Minimize Personally Identifiable Informationno data