id: "SA-15(01)" title: "Quality Metrics" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-15.01" priority: "P1" implementation_level: "organization" parent: "SA-15" enhancement: True


Statement

Require the developer of the system, system component, or system service to:

Define quality metrics at the beginning of the development process; and

Provide evidence of meeting the quality metrics {{ insert: param, sa-15.01_odp.01 }}.

Guidance

Organizations use quality metrics to establish acceptable levels of system quality. Metrics can include quality gates, which are collections of completion criteria or sufficiency standards that represent the satisfactory execution of specific phases of the system development project. For example, a quality gate may require the elimination of all compiler warnings or a determination that such warnings have no impact on the effectiveness of required security or privacy capabilities. During the execution phases of development projects, quality gates provide clear, unambiguous indications of progress. Other metrics apply to the entire development project. Metrics can include defining the severity thresholds of vulnerabilities in accordance with organizational risk tolerance, such as requiring no known vulnerabilities in the delivered system with a Common Vulnerability Scoring System (CVSS) severity of medium or high.

Assessment Objective: the developer of the system, system component, or system service is required to define quality metrics at the beginning of the development process;

Assessment Objective: the developer of the system, system component, or system service is required to provide evidence of meeting the quality metrics {{ insert: param, sa-15.01_odp.01 }}.

System and services acquisition policy

procedures addressing development process, standards, and tools

procedures addressing the integration of security requirements into the acquisition process

solicitation documentation

acquisition documentation

service level agreements

acquisition contracts for the system, system component, or system service

list of quality metrics

documentation evidence of meeting quality metrics

system security plan

other relevant documents or records

Organizational personnel with system and service acquisition responsibilities

organizational personnel with information security responsibilities

system developer