💼 SA-17 Developer Security and Privacy Architecture and Design
- Contextual name: 💼 SA-17 Developer Security and Privacy Architecture and Design
- ID:
/frameworks/nist-sp-800-53-r5/sa/17
- Located in: 💼 SA System And Services Acquisition
Description​
Require the developer of the system, system component, or system service to produce a design specification and security and privacy architecture that: a. Is consistent with the organization’s security and privacy architecture that is an integral part the organization’s enterprise architecture; b. Accurately and completely describes the required security and privacy functionality, and the allocation of controls among physical and logical components; and c. Expresses how individual security and privacy functions, mechanisms, and services work together to provide required security and privacy capabilities and a unified approach to protection.
Similar​
- Internal
- ID:
dec-c-086554dc
- ID:
Similar Sections (Give Policies To)​
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
💼 FedRAMP High Security Controls → 💼 SA-17 Developer Security and Privacy Architecture and Design (H) | ||||
💼 NIST CSF v2.0 → 💼 ID.RA-09: The authenticity and integrity of hardware and software are assessed prior to acquisition and use | 4 |