id: "SA-04(03)" title: "Development Methods, Techniques, and Practices" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-04.03" priority: "P1" implementation_level: "organization" parent: "SA-04" enhancement: True
Statement
Require the developer of the system, system component, or system service to demonstrate the use of a system development life cycle process that includes:
{{ insert: param, sa-04.03_odp.01 }};
{{ insert: param, sa-04.03_odp.02 }} ; and
{{ insert: param, sa-04.03_odp.05 }}.
Guidance
Following a system development life cycle that includes state-of-the-practice software development methods, systems engineering methods, systems security and privacy engineering methods, and quality control processes helps to reduce the number and severity of latent errors within systems, system components, and system services. Reducing the number and severity of such errors reduces the number of vulnerabilities in those systems, components, and services. Transparency in the methods and techniques that developers select and implement for systems engineering, systems security and privacy engineering, software development, component and system assessments, and quality control processes provides an increased level of assurance in the trustworthiness of the system, system component, or system service being acquired.
Assessment Objective: the developer of the system, system component, or system service is required to demonstrate the use of a system development life cycle process that includes {{ insert: param, sa-04.03_odp.01 }};
Assessment Objective: the developer of the system, system component, or system service is required to demonstrate the use of a system development life cycle process that includes {{ insert: param, sa-04.03_odp.02 }};
Assessment Objective: the developer of the system, system component, or system service is required to demonstrate the use of a system development life cycle process that includes {{ insert: param, sa-04.03_odp.05 }}.
System and services acquisition policy
system and services acquisition procedures
procedures addressing the integration of security and privacy requirements, descriptions, and criteria into the acquisition process
solicitation documents
acquisition documentation
acquisition contracts for the system, system component, or system service
list of systems security and privacy engineering methods to be included in the developer’s system development life cycle process
list of software development methods to be included in the developer’s system development life cycle process
list of testing, evaluation, or validation techniques to be included in the developer’s system development life cycle process
list of quality control processes to be included in the developer’s system development life cycle process
system security plan
privacy plan
other relevant documents or records
Organizational personnel with acquisition/contracting responsibilities
organizational personnel with information security and privacy responsibilities
organizational personnel with system life cycle responsibilities
system developers or service provider
Organizational processes for development methods, techniques, and processes