id: "SA-11(01)" title: "Static Code Analysis" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-11.01" priority: "P1" implementation_level: "organization" parent: "SA-11" enhancement: True
Statement
Require the developer of the system, system component, or system service to employ static code analysis tools to identify common flaws and document the results of the analysis.
Guidance
Static code analysis provides a technology and methodology for security reviews and includes checking for weaknesses in the code as well as for the incorporation of libraries or other included code with known vulnerabilities or that are out-of-date and not supported. Static code analysis can be used to identify vulnerabilities and enforce secure coding practices. It is most effective when used early in the development process, when each code change can automatically be scanned for potential weaknesses. Static code analysis can provide clear remediation guidance and identify defects for developers to fix. Evidence of the correct implementation of static analysis can include aggregate defect density for critical defect types, evidence that defects were inspected by developers or security professionals, and evidence that defects were remediated. A high density of ignored findings, commonly referred to as false positives, indicates a potential problem with the analysis process or the analysis tool. In such cases, organizations weigh the validity of the evidence against evidence from other sources.
Assessment Objective: the developer of the system, system component, or system service is required to employ static code analysis tools to identify common flaws;
Assessment Objective: the developer of the system, system component, or system service is required to employ static code analysis tools to document the results of the analysis.
System and services acquisition policy
system and services acquisition procedures
procedures addressing system developer security testing
procedures addressing flaw remediation
solicitation documentation
acquisition documentation
service level agreements
acquisition contracts for the system, system component, or system service
security and privacy architecture
system design documentation
system developer security and privacy assessment plans
results of system developer security and privacy assessments
security flaw and remediation tracking records
system security plan
privacy plan
privacy impact assessment
privacy risk assessment documentation
other relevant documents or records
Organizational personnel with system and service acquisition responsibilities
organizational personnel with information security responsibilities
organizational personnel with developer security and privacy testing responsibilities
organizational personnel with configuration management responsibilities
system developers
Organizational processes for monitoring developer security testing and evaluation
mechanisms supporting and/or implementing the monitoring of developer security testing and evaluation
static code analysis tools