id: "SA-15(07)" title: "Automated Vulnerability Analysis" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-15.07" priority: "P1" implementation_level: "organization" parent: "SA-15" enhancement: True
Statement
Require the developer of the system, system component, or system service {{ insert: param, sa-15.07_odp.01 }} to:
Perform an automated vulnerability analysis using {{ insert: param, sa-15.07_odp.02 }};
Determine the exploitation potential for discovered vulnerabilities;
Determine potential risk mitigations for delivered vulnerabilities; and
Deliver the outputs of the tools and results of the analysis to {{ insert: param, sa-15.07_odp.03 }}.
Guidance
Automated tools can be more effective at analyzing exploitable weaknesses or deficiencies in large and complex systems, prioritizing vulnerabilities by severity, and providing recommendations for risk mitigations.
Assessment Objective: the developer of the system, system component, or system service is required to perform automated vulnerability analysis {{ insert: param, sa-15.07_odp.01 }} using {{ insert: param, sa-15.07_odp.02 }};
Assessment Objective: the developer of the system, system component, or system service is required to determine the exploitation potential for discovered vulnerabilities {{ insert: param, sa-15.07_odp.01 }};
Assessment Objective: the developer of the system, system component, or system service is required to determine potential risk mitigations {{ insert: param, sa-15.07_odp.01 }} for delivered vulnerabilities;
Assessment Objective: the developer of the system, system component, or system service is required to deliver the outputs of the tools and results of the analysis {{ insert: param, sa-15.07_odp.01 }} to {{ insert: param, sa-15.07_odp.03 }}.
System and services acquisition policy
procedures addressing development process, standards, and tools
solicitation documentation
acquisition documentation
service level agreements
acquisition contracts for the system, system component, or system service
vulnerability analysis tools and associated documentation
risk assessment reports
vulnerability analysis results
vulnerability mitigation reports
risk mitigation strategy documentation
system security plan
other relevant documents or records
Organizational personnel with system and service acquisition responsibilities
organizational personnel with information security responsibilities
system developer
organizational personnel performing automated vulnerability analysis on the system
Organizational processes for vulnerability analysis of systems, system components, or system services under development
mechanisms supporting and/or implementing vulnerability analysis of systems, system components, or system services under development