id: "SA-04(03)" title: "Development Methods, Techniques, and Practices" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-04.03" priority: "P1" implementation_level: "organization" parent: "SA-04" enhancement: True


Statement

Require the developer of the system, system component, or system service to demonstrate the use of a system development life cycle process that includes:

{{ insert: param, sa-04.03_odp.01 }};

{{ insert: param, sa-04.03_odp.02 }} ; and

{{ insert: param, sa-04.03_odp.05 }}.

Guidance

Following a system development life cycle that includes state-of-the-practice software development methods, systems engineering methods, systems security and privacy engineering methods, and quality control processes helps to reduce the number and severity of latent errors within systems, system components, and system services. Reducing the number and severity of such errors reduces the number of vulnerabilities in those systems, components, and services. Transparency in the methods and techniques that developers select and implement for systems engineering, systems security and privacy engineering, software development, component and system assessments, and quality control processes provides an increased level of assurance in the trustworthiness of the system, system component, or system service being acquired.

Assessment Objective: the developer of the system, system component, or system service is required to demonstrate the use of a system development life cycle process that includes {{ insert: param, sa-04.03_odp.01 }};

Assessment Objective: the developer of the system, system component, or system service is required to demonstrate the use of a system development life cycle process that includes {{ insert: param, sa-04.03_odp.02 }};

Assessment Objective: the developer of the system, system component, or system service is required to demonstrate the use of a system development life cycle process that includes {{ insert: param, sa-04.03_odp.05 }}.

System and services acquisition policy

system and services acquisition procedures

procedures addressing the integration of security and privacy requirements, descriptions, and criteria into the acquisition process

solicitation documents

acquisition documentation

acquisition contracts for the system, system component, or system service

list of systems security and privacy engineering methods to be included in the developer’s system development life cycle process

list of software development methods to be included in the developer’s system development life cycle process

list of testing, evaluation, or validation techniques to be included in the developer’s system development life cycle process

list of quality control processes to be included in the developer’s system development life cycle process

system security plan

privacy plan

other relevant documents or records

Organizational personnel with acquisition/contracting responsibilities

organizational personnel with information security and privacy responsibilities

organizational personnel with system life cycle responsibilities

system developers or service provider

Organizational processes for development methods, techniques, and processes