id: "SA-11(03)" title: "Independent Verification of Assessment Plans and Evidence" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-11.03" priority: "P1" implementation_level: "organization" parent: "SA-11" enhancement: True
Require an independent agent satisfying {{ insert: param, sa-11.03_odp }} to verify the correct implementation of the developer security and privacy assessment plans and the evidence produced during testing and evaluation; and
Verify that the independent agent is provided with sufficient information to complete the verification process or granted the authority to obtain such information.
Guidance
Independent agents have the qualifications—including the expertise, skills, training, certifications, and experience—to verify the correct implementation of developer security and privacy assessment plans.
Assessment Objective: an independent agent is required to satisfy {{ insert: param, sa-11.03_odp }} to verify the correct implementation of the developer security assessment plan and the evidence produced during testing and evaluation;
Assessment Objective: an independent agent is required to satisfy {{ insert: param, sa-11.03_odp }} to verify the correct implementation of the developer privacy assessment plan and the evidence produced during testing and evaluation;
Assessment Objective: the independent agent is provided with sufficient information to complete the verification process or granted the authority to obtain such information.
System and services acquisition policy
system and services acquisition procedures
procedures addressing system developer security testing
solicitation documentation
acquisition documentation
service level agreements
acquisition contracts for the system, system component, or system service
independent verification and validation reports
security and privacy assessment plans
results of security and privacy assessments for the system, system component, or system service
system security plan
privacy plan
privacy program plan
other relevant documents or records
Organizational personnel with system and service acquisition responsibilities
organizational personnel with information security and privacy responsibilities
organizational personnel with developer security testing responsibilities
system developers
independent verification agent
Organizational processes for monitoring developer security testing and evaluation
mechanisms supporting and/or implementing the monitoring of developer security testing and evaluation