πΌ SA-15 Development Process, Standards, and Tools
- Contextual name: πΌ SA-15 Development Process, Standards, and Tools
- ID:
/frameworks/nist-sp-800-53-r5/sa/15
- Located in: πΌ SA System And Services Acquisition
Descriptionβ
a. Require the developer of the system, system component, or system service to follow a documented development process that:
- Explicitly addresses security and privacy requirements;
- Identifies the standards and tools used in the development process;
- Documents the specific tool options and tool configurations used in the development process; and
- Documents, manages, and ensures the integrity of changes to the process and/or tools used in development; and b. Review the development process, standards, tools, tool options, and tool configurations [Assignment: organization-defined frequency] to determine if the process, standards, tools, tool options and tool configurations selected and employed can satisfy the following security and privacy requirements: [Assignment: organization-defined security and privacy requirements].
Similarβ
- Internal
- ID:
dec-c-1590f8ea
- ID:
Similar Sections (Give Policies To)β
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ NIST CSF v2.0 β πΌ ID.RA-09: The authenticity and integrity of hardware and software are assessed prior to acquisition and use |