Skip to main content

💼 SA-17(1) Developer Security and Privacy Architecture and Design | Formal Policy Model

Description​

Require the developer of the system, system component, or system service to: (a) Produce, as an integral part of the development process, a formal policy model describing the [Assignment: organization-defined elements of organizational security and privacy policy] to be enforced; and (b) Prove that the formal policy model is internally consistent and sufficient to enforce the defined elements of the organizational security and privacy policy when implemented.

Similar​

  • Internal
    • ID: dec-c-9f5cfa48

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags