id: "SA-11(06)" title: "Attack Surface Reviews" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-11.06" priority: "P1" implementation_level: "organization" parent: "SA-11" enhancement: True
Statement
Require the developer of the system, system component, or system service to perform attack surface reviews.
Guidance
Attack surfaces of systems and system components are exposed areas that make those systems more vulnerable to attacks. Attack surfaces include any accessible areas where weaknesses or deficiencies in the hardware, software, and firmware components provide opportunities for adversaries to exploit vulnerabilities. Attack surface reviews ensure that developers analyze the design and implementation changes to systems and mitigate attack vectors generated as a result of the changes. The correction of identified flaws includes deprecation of unsafe functions.
Assessment Objective
the developer of the system, system component, or system service is required to perform attack surface reviews.
System and services acquisition policy
procedures addressing system developer security testing
solicitation documentation
acquisition documentation
service level agreements
acquisition contracts for the system, system component, or system service
system developer security testing and evaluation plans
system developer security testing and evaluation results
records of attack surface reviews
system security plan
other relevant documents or records
Organizational personnel with system and service acquisition responsibilities
organizational personnel with information security responsibilities
organizational personnel with developer security testing responsibilities
organizational personnel with configuration management responsibilities
system developers
Organizational processes for monitoring developer security testing and evaluation
mechanisms supporting and/or implementing the monitoring of developer security testing and evaluation