id: "SA-15(11)" title: "Archive System or Component" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-15.11" priority: "P1" implementation_level: "organization" parent: "SA-15" enhancement: True
Statement
Require the developer of the system or system component to archive the system or component to be released or delivered together with the corresponding evidence supporting the final security and privacy review.
Guidance
Archiving system or system components requires the developer to retain key development artifacts, including hardware specifications, source code, object code, and relevant documentation from the development process that can provide a readily available configuration baseline for system and component upgrades or modifications.
Assessment Objective
the developer of the system or system component is required to archive the system or component to be released or delivered together with the corresponding evidence supporting the final security and privacy review.
System and services acquisition policy
procedures addressing development process, standards, and tools
solicitation documentation
acquisition documentation
service level agreements
acquisition contracts for the system or system component
evidence of archived system or component
system security plan
privacy plan
other relevant documents or records
Organizational personnel with system and service acquisition responsibilities
organizational personnel with information security responsibilities
system developer
organizational personnel with privacy responsibilities