id: "SA-11(03)" title: "Independent Verification of Assessment Plans and Evidence" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-11.03" priority: "P1" implementation_level: "organization" parent: "SA-11" enhancement: True


Require an independent agent satisfying {{ insert: param, sa-11.03_odp }} to verify the correct implementation of the developer security and privacy assessment plans and the evidence produced during testing and evaluation; and

Verify that the independent agent is provided with sufficient information to complete the verification process or granted the authority to obtain such information.

Guidance

Independent agents have the qualifications—including the expertise, skills, training, certifications, and experience—to verify the correct implementation of developer security and privacy assessment plans.

Assessment Objective: an independent agent is required to satisfy {{ insert: param, sa-11.03_odp }} to verify the correct implementation of the developer security assessment plan and the evidence produced during testing and evaluation;

Assessment Objective: an independent agent is required to satisfy {{ insert: param, sa-11.03_odp }} to verify the correct implementation of the developer privacy assessment plan and the evidence produced during testing and evaluation;

Assessment Objective: the independent agent is provided with sufficient information to complete the verification process or granted the authority to obtain such information.

System and services acquisition policy

system and services acquisition procedures

procedures addressing system developer security testing

solicitation documentation

acquisition documentation

service level agreements

acquisition contracts for the system, system component, or system service

independent verification and validation reports

security and privacy assessment plans

results of security and privacy assessments for the system, system component, or system service

system security plan

privacy plan

privacy program plan

other relevant documents or records

Organizational personnel with system and service acquisition responsibilities

organizational personnel with information security and privacy responsibilities

organizational personnel with developer security testing responsibilities

system developers

independent verification agent

Organizational processes for monitoring developer security testing and evaluation

mechanisms supporting and/or implementing the monitoring of developer security testing and evaluation