id: "SA-11(04)" title: "Manual Code Reviews" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-11.04" priority: "P1" implementation_level: "organization" parent: "SA-11" enhancement: True


Statement

Require the developer of the system, system component, or system service to perform a manual code review of {{ insert: param, sa-11.04_odp.01 }} using the following processes, procedures, and/or techniques: {{ insert: param, sa-11.04_odp.02 }}.

Guidance

Manual code reviews are usually reserved for the critical software and firmware components of systems. Manual code reviews are effective at identifying weaknesses that require knowledge of the application’s requirements or context that, in most cases, is unavailable to automated analytic tools and techniques, such as static and dynamic analysis. The benefits of manual code review include the ability to verify access control matrices against application controls and review detailed aspects of cryptographic implementations and controls.

Assessment Objective

the developer of the system, system component, or system service is required to perform a manual code review of {{ insert: param, sa-11.04_odp.01 }} using {{ insert: param, sa-11.04_odp.02 }}.

System and services acquisition policy

procedures addressing system developer security testing

processes, procedures, and/or techniques for performing manual code reviews

solicitation documentation

acquisition documentation

service level agreements

acquisition contracts for the system, system component, or system service

system developer security testing and evaluation plans

system developer security testing and evaluation results

list of code requiring manual reviews

records of manual code reviews

system security plan

other relevant documents or records

Organizational personnel with system and service acquisition responsibilities

organizational personnel with information security responsibilities

organizational personnel with developer security testing responsibilities

system developers

independent verification agent

Organizational processes for monitoring developer security testing and evaluation

mechanisms supporting and/or implementing the monitoring of developer testing and evaluation