id: "SA-15(07)" title: "Automated Vulnerability Analysis" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-15.07" priority: "P1" implementation_level: "organization" parent: "SA-15" enhancement: True


Statement

Require the developer of the system, system component, or system service {{ insert: param, sa-15.07_odp.01 }} to:

Perform an automated vulnerability analysis using {{ insert: param, sa-15.07_odp.02 }};

Determine the exploitation potential for discovered vulnerabilities;

Determine potential risk mitigations for delivered vulnerabilities; and

Deliver the outputs of the tools and results of the analysis to {{ insert: param, sa-15.07_odp.03 }}.

Guidance

Automated tools can be more effective at analyzing exploitable weaknesses or deficiencies in large and complex systems, prioritizing vulnerabilities by severity, and providing recommendations for risk mitigations.

Assessment Objective: the developer of the system, system component, or system service is required to perform automated vulnerability analysis {{ insert: param, sa-15.07_odp.01 }} using {{ insert: param, sa-15.07_odp.02 }};

Assessment Objective: the developer of the system, system component, or system service is required to determine the exploitation potential for discovered vulnerabilities {{ insert: param, sa-15.07_odp.01 }};

Assessment Objective: the developer of the system, system component, or system service is required to determine potential risk mitigations {{ insert: param, sa-15.07_odp.01 }} for delivered vulnerabilities;

Assessment Objective: the developer of the system, system component, or system service is required to deliver the outputs of the tools and results of the analysis {{ insert: param, sa-15.07_odp.01 }} to {{ insert: param, sa-15.07_odp.03 }}.

System and services acquisition policy

procedures addressing development process, standards, and tools

solicitation documentation

acquisition documentation

service level agreements

acquisition contracts for the system, system component, or system service

vulnerability analysis tools and associated documentation

risk assessment reports

vulnerability analysis results

vulnerability mitigation reports

risk mitigation strategy documentation

system security plan

other relevant documents or records

Organizational personnel with system and service acquisition responsibilities

organizational personnel with information security responsibilities

system developer

organizational personnel performing automated vulnerability analysis on the system

Organizational processes for vulnerability analysis of systems, system components, or system services under development

mechanisms supporting and/or implementing vulnerability analysis of systems, system components, or system services under development