Skip to main content

πŸ’Ό SA-15 Development Process, Standards, and Tools

  • Contextual name: πŸ’Ό SA-15 Development Process, Standards, and Tools
  • ID: /frameworks/nist-sp-800-53-r5/sa/15
  • Located in: πŸ’Ό SA System And Services Acquisition

Description​

a. Require the developer of the system, system component, or system service to follow a documented development process that:

  1. Explicitly addresses security and privacy requirements;
  2. Identifies the standards and tools used in the development process;
  3. Documents the specific tool options and tool configurations used in the development process; and
  4. Documents, manages, and ensures the integrity of changes to the process and/or tools used in development; and b. Review the development process, standards, tools, tool options, and tool configurations [Assignment: organization-defined frequency] to determine if the process, standards, tools, tool options and tool configurations selected and employed can satisfy the following security and privacy requirements: [Assignment: organization-defined security and privacy requirements].

Similar​

  • Internal
    • ID: dec-c-1590f8ea

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό ID.RA-09: The authenticity and integrity of hardware and software are assessed prior to acquisition and use

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό SA-15(1) Development Process, Standards, and Tools _ Quality Metrics
πŸ’Ό SA-15(2) Development Process, Standards, and Tools _ Security and Privacy Tracking Tools
πŸ’Ό SA-15(3) Development Process, Standards, and Tools _ Criticality Analysis
πŸ’Ό SA-15(4) Development Process, Standards, and Tools _ Threat Modeling and Vulnerability Analysis
πŸ’Ό SA-15(5) Development Process, Standards, and Tools _ Attack Surface Reduction
πŸ’Ό SA-15(6) Development Process, Standards, and Tools _ Continuous Improvement
πŸ’Ό SA-15(7) Development Process, Standards, and Tools _ Automated Vulnerability Analysis
πŸ’Ό SA-15(8) Development Process, Standards, and Tools _ Reuse of Threat and Vulnerability Information
πŸ’Ό SA-15(9) Development Process, Standards, and Tools _ Use of Live Data
πŸ’Ό SA-15(10) Development Process, Standards, and Tools _ Incident Response Plan
πŸ’Ό SA-15(11) Development Process, Standards, and Tools _ Archive System or Component
πŸ’Ό SA-15(12) Development Process, Standards, and Tools _ Minimize Personally Identifiable Information