id: "SA-15(11)" title: "Archive System or Component" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-15.11" priority: "P1" implementation_level: "organization" parent: "SA-15" enhancement: True


Statement

Require the developer of the system or system component to archive the system or component to be released or delivered together with the corresponding evidence supporting the final security and privacy review.

Guidance

Archiving system or system components requires the developer to retain key development artifacts, including hardware specifications, source code, object code, and relevant documentation from the development process that can provide a readily available configuration baseline for system and component upgrades or modifications.

Assessment Objective

the developer of the system or system component is required to archive the system or component to be released or delivered together with the corresponding evidence supporting the final security and privacy review.

System and services acquisition policy

procedures addressing development process, standards, and tools

solicitation documentation

acquisition documentation

service level agreements

acquisition contracts for the system or system component

evidence of archived system or component

system security plan

privacy plan

other relevant documents or records

Organizational personnel with system and service acquisition responsibilities

organizational personnel with information security responsibilities

system developer

organizational personnel with privacy responsibilities