id: "SA-08(30)" title: "Procedural Rigor" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-08.30" priority: "P1" implementation_level: "system" parent: "SA-08" enhancement: True


Statement

Implement the security design principle of procedural rigor in {{ insert: param, sa-08.30_odp }}.

Guidance

The principle of procedural rigor states that the rigor of a system life cycle process is commensurate with its intended trustworthiness. Procedural rigor defines the scope, depth, and detail of the system life cycle procedures. Rigorous system life cycle procedures contribute to the assurance that the system is correct and free of unintended functionality in several ways. First, the procedures impose checks and balances on the life cycle process such that the introduction of unspecified functionality is prevented.

Second, rigorous procedures applied to systems security engineering activities that produce specifications and other system design documents contribute to the ability to understand the system as it has been built rather than trusting that the component, as implemented, is the authoritative (and potentially misleading) specification.

Finally, modifications to an existing system component are easier when there are detailed specifications that describe its current design instead of studying source code or schematics to try to understand how it works. Procedural rigor helps ensure that security functional and assurance requirements have been satisfied, and it contributes to a better-informed basis for the determination of trustworthiness and risk posture. Procedural rigor is commensurate with the degree of assurance desired for the system. If the required trustworthiness of the system is low, a high level of procedural rigor may add unnecessary cost, whereas when high trustworthiness is critical, the cost of high procedural rigor is merited.

Assessment Objective

{{ insert: param, sa-08.30_odp }} implement the security design principle of procedural rigor.

System and services acquisition policy

procedures addressing the security design principle of procedural rigor used in the specification, design, development, implementation, and modification of the system

system design documentation

security and privacy requirements and specifications for the system

system security and privacy architecture

system security plan

other relevant documents or records

Organizational personnel with the responsibility for determining system security and privacy requirements

organizational personnel with system specification, design, development, implementation, and modification responsibilities

system developers

organizational personnel with information security responsibilities

Organizational processes for applying the security design principle of procedural rigor in system specification, design, development, implementation, and modification

mechanisms supporting the application of the security design principle of procedural rigor in system specification, design, development, implementation, and modification

mechanisms that enforce security policies