Organizational Control: Developer Security Architecture And Design
Control ID: SA-17 Developer Security Architecture And Design | Family: System and Services Acquisition | Source: NIST 800-53r4 |
Control: The organization requires the developer of the information system, system component, or information system service to produce a design specification and security architecture that:
|
||
Supplemental Guidance: This control is primarily directed at external developers, although it could also be used for internal (in-house) development. In contrast, PL-8 is primarily directed at internal developers to help ensure that organizations develop an information security architecture and such security architecture is integrated or tightly coupled to the enterprise architecture. This distinction is important if/when organizations outsource the development of information systems, information system components, or information system services to external entities, and there is a requirement to demonstrate consistency with the organization's enterprise architecture and information security architecture. Related Controls: PL-8, SA-3, SA-8, PM-7 |
||
Control Enhancements: N/A | ||
References: N/A | ||
Mechanisms: | ||
Protocol Implementation Conformance Statements: N/A |