Skip to main content

๐Ÿ’ผ SA-17 Developer Security and Privacy Architecture and Design

  • Contextual name: ๐Ÿ’ผ SA-17 Developer Security and Privacy Architecture and Design
  • ID: /frameworks/nist-sp-800-53-r5/sa/17
  • Located in: ๐Ÿ’ผ SA System And Services Acquisition

Descriptionโ€‹

Require the developer of the system, system component, or system service to produce a design specification and security and privacy architecture that: a. Is consistent with the organizationโ€™s security and privacy architecture that is an integral part the organizationโ€™s enterprise architecture; b. Accurately and completely describes the required security and privacy functionality, and the allocation of controls among physical and logical components; and c. Expresses how individual security and privacy functions, mechanisms, and services work together to provide required security and privacy capabilities and a unified approach to protection.

Similarโ€‹

  • Internal
    • ID: dec-c-086554dc

Similar Sections (Give Policies To)โ€‹

SectionSub SectionsInternal RulesPoliciesFlags
๐Ÿ’ผ FedRAMP High Security Controls โ†’ ๐Ÿ’ผ SA-17 Developer Security and Privacy Architecture and Design (H)
๐Ÿ’ผ NIST CSF v2.0 โ†’ ๐Ÿ’ผ ID.RA-09: The authenticity and integrity of hardware and software are assessed prior to acquisition and use

Sub Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlags
๐Ÿ’ผ SA-17(1) Developer Security and Privacy Architecture and Design _ Formal Policy Model
๐Ÿ’ผ SA-17(2) Developer Security and Privacy Architecture and Design _ Security-relevant Components
๐Ÿ’ผ SA-17(3) Developer Security and Privacy Architecture and Design _ Formal Correspondence
๐Ÿ’ผ SA-17(4) Developer Security and Privacy Architecture and Design _ Informal Correspondence
๐Ÿ’ผ SA-17(5) Developer Security and Privacy Architecture and Design _ Conceptually Simple Design
๐Ÿ’ผ SA-17(6) Developer Security and Privacy Architecture and Design _ Structure for Testing
๐Ÿ’ผ SA-17(7) Developer Security and Privacy Architecture and Design _ Structure for Least Privilege
๐Ÿ’ผ SA-17(8) Developer Security and Privacy Architecture and Design _ Orchestration
๐Ÿ’ผ SA-17(9) Developer Security and Privacy Architecture and Design _ Design Diversity