id: "SA-15(01)" title: "Quality Metrics" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-15.01" priority: "P1" implementation_level: "organization" parent: "SA-15" enhancement: True
Statement
Require the developer of the system, system component, or system service to:
Define quality metrics at the beginning of the development process; and
Provide evidence of meeting the quality metrics {{ insert: param, sa-15.01_odp.01 }}.
Guidance
Organizations use quality metrics to establish acceptable levels of system quality. Metrics can include quality gates, which are collections of completion criteria or sufficiency standards that represent the satisfactory execution of specific phases of the system development project. For example, a quality gate may require the elimination of all compiler warnings or a determination that such warnings have no impact on the effectiveness of required security or privacy capabilities. During the execution phases of development projects, quality gates provide clear, unambiguous indications of progress. Other metrics apply to the entire development project. Metrics can include defining the severity thresholds of vulnerabilities in accordance with organizational risk tolerance, such as requiring no known vulnerabilities in the delivered system with a Common Vulnerability Scoring System (CVSS) severity of medium or high.
Assessment Objective: the developer of the system, system component, or system service is required to define quality metrics at the beginning of the development process;
Assessment Objective: the developer of the system, system component, or system service is required to provide evidence of meeting the quality metrics {{ insert: param, sa-15.01_odp.01 }}.
System and services acquisition policy
procedures addressing development process, standards, and tools
procedures addressing the integration of security requirements into the acquisition process
solicitation documentation
acquisition documentation
service level agreements
acquisition contracts for the system, system component, or system service
list of quality metrics
documentation evidence of meeting quality metrics
system security plan
other relevant documents or records
Organizational personnel with system and service acquisition responsibilities
organizational personnel with information security responsibilities
system developer