id: "SA-11(01)" title: "Static Code Analysis" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-11.01" priority: "P1" implementation_level: "organization" parent: "SA-11" enhancement: True


Statement

Require the developer of the system, system component, or system service to employ static code analysis tools to identify common flaws and document the results of the analysis.

Guidance

Static code analysis provides a technology and methodology for security reviews and includes checking for weaknesses in the code as well as for the incorporation of libraries or other included code with known vulnerabilities or that are out-of-date and not supported. Static code analysis can be used to identify vulnerabilities and enforce secure coding practices. It is most effective when used early in the development process, when each code change can automatically be scanned for potential weaknesses. Static code analysis can provide clear remediation guidance and identify defects for developers to fix. Evidence of the correct implementation of static analysis can include aggregate defect density for critical defect types, evidence that defects were inspected by developers or security professionals, and evidence that defects were remediated. A high density of ignored findings, commonly referred to as false positives, indicates a potential problem with the analysis process or the analysis tool. In such cases, organizations weigh the validity of the evidence against evidence from other sources.

Assessment Objective: the developer of the system, system component, or system service is required to employ static code analysis tools to identify common flaws;

Assessment Objective: the developer of the system, system component, or system service is required to employ static code analysis tools to document the results of the analysis.

System and services acquisition policy

system and services acquisition procedures

procedures addressing system developer security testing

procedures addressing flaw remediation

solicitation documentation

acquisition documentation

service level agreements

acquisition contracts for the system, system component, or system service

security and privacy architecture

system design documentation

system developer security and privacy assessment plans

results of system developer security and privacy assessments

security flaw and remediation tracking records

system security plan

privacy plan

privacy impact assessment

privacy risk assessment documentation

other relevant documents or records

Organizational personnel with system and service acquisition responsibilities

organizational personnel with information security responsibilities

organizational personnel with developer security and privacy testing responsibilities

organizational personnel with configuration management responsibilities

system developers

Organizational processes for monitoring developer security testing and evaluation

mechanisms supporting and/or implementing the monitoring of developer security testing and evaluation

static code analysis tools