id: "SA-11(06)" title: "Attack Surface Reviews" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-11.06" priority: "P1" implementation_level: "organization" parent: "SA-11" enhancement: True


Statement

Require the developer of the system, system component, or system service to perform attack surface reviews.

Guidance

Attack surfaces of systems and system components are exposed areas that make those systems more vulnerable to attacks. Attack surfaces include any accessible areas where weaknesses or deficiencies in the hardware, software, and firmware components provide opportunities for adversaries to exploit vulnerabilities. Attack surface reviews ensure that developers analyze the design and implementation changes to systems and mitigate attack vectors generated as a result of the changes. The correction of identified flaws includes deprecation of unsafe functions.

Assessment Objective

the developer of the system, system component, or system service is required to perform attack surface reviews.

System and services acquisition policy

procedures addressing system developer security testing

solicitation documentation

acquisition documentation

service level agreements

acquisition contracts for the system, system component, or system service

system developer security testing and evaluation plans

system developer security testing and evaluation results

records of attack surface reviews

system security plan

other relevant documents or records

Organizational personnel with system and service acquisition responsibilities

organizational personnel with information security responsibilities

organizational personnel with developer security testing responsibilities

organizational personnel with configuration management responsibilities

system developers

Organizational processes for monitoring developer security testing and evaluation

mechanisms supporting and/or implementing the monitoring of developer security testing and evaluation