id: "SA-11(04)" title: "Manual Code Reviews" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-11.04" priority: "P1" implementation_level: "organization" parent: "SA-11" enhancement: True
Statement
Require the developer of the system, system component, or system service to perform a manual code review of {{ insert: param, sa-11.04_odp.01 }} using the following processes, procedures, and/or techniques: {{ insert: param, sa-11.04_odp.02 }}.
Guidance
Manual code reviews are usually reserved for the critical software and firmware components of systems. Manual code reviews are effective at identifying weaknesses that require knowledge of the application’s requirements or context that, in most cases, is unavailable to automated analytic tools and techniques, such as static and dynamic analysis. The benefits of manual code review include the ability to verify access control matrices against application controls and review detailed aspects of cryptographic implementations and controls.
Assessment Objective
the developer of the system, system component, or system service is required to perform a manual code review of {{ insert: param, sa-11.04_odp.01 }} using {{ insert: param, sa-11.04_odp.02 }}.
System and services acquisition policy
procedures addressing system developer security testing
processes, procedures, and/or techniques for performing manual code reviews
solicitation documentation
acquisition documentation
service level agreements
acquisition contracts for the system, system component, or system service
system developer security testing and evaluation plans
system developer security testing and evaluation results
list of code requiring manual reviews
records of manual code reviews
system security plan
other relevant documents or records
Organizational personnel with system and service acquisition responsibilities
organizational personnel with information security responsibilities
organizational personnel with developer security testing responsibilities
system developers
independent verification agent
Organizational processes for monitoring developer security testing and evaluation
mechanisms supporting and/or implementing the monitoring of developer testing and evaluation