id: "SA-08(31)" title: "Secure System Modification" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-08.31" priority: "P1" implementation_level: "system" parent: "SA-08" enhancement: True


Statement

Implement the security design principle of secure system modification in {{ insert: param, sa-08.31_odp }}.

Guidance

The principle of secure system modification states that system modification maintains system security with respect to the security requirements and risk tolerance of stakeholders. Upgrades or modifications to systems can transform secure systems into systems that are not secure. The procedures for system modification ensure that if the system is to maintain its trustworthiness, the same rigor that was applied to its initial development is applied to any system changes. Because modifications can affect the ability of the system to maintain its secure state, a careful security analysis of the modification is needed prior to its implementation and deployment. This principle parallels the principle of secure evolvability.

Assessment Objective

{{ insert: param, sa-08.31_odp }} implement the security design principle of secure system modification.

System and services acquisition policy

configuration management policy and procedures

procedures addressing the security design principle of secure system modification used in the specification, design, development, implementation, and modification of the system

system design documentation

system configuration settings and associated documentation

change control records

security and privacy requirements and specifications for the system

system security and privacy architecture

system security plan

other relevant documents or records

Organizational personnel with the responsibility for determining system security and privacy requirements

organizational personnel with system specification, design, development, implementation, and modification responsibilities

system developers

organizational personnel with information security responsibilities

Organizational processes for applying the security design principle of secure system modification in system specification, design, development, implementation, and modification

mechanisms supporting the application of the security design principle of secure system modification in system specification, design, development, implementation, and modification

mechanisms that enforce security policies

organizational processes for managing change configuration

mechanisms supporting configuration control