id: "SA-17" title: "Developer Security and Privacy Architecture and Design" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-17" priority: "P1" implementation_level: "organization" enhancements: - sa-17.1 - sa-17.2 - sa-17.3 - sa-17.4 - sa-17.5 - sa-17.6 - sa-17.7 - sa-17.8 - sa-17.9
Statement
Require the developer of the system, system component, or system service to produce a design specification and security and privacy architecture that:
Is consistent with the organization’s security and privacy architecture that is an integral part the organization’s enterprise architecture;
Accurately and completely describes the required security and privacy functionality, and the allocation of controls among physical and logical components; and
Expresses how individual security and privacy functions, mechanisms, and services work together to provide required security and privacy capabilities and a unified approach to protection.
Guidance
Developer security and privacy architecture and design are directed at external developers, although they could also be applied to internal (in-house) development. In contrast, PL-8 is directed at internal developers to ensure that organizations develop a security and privacy architecture that is integrated with the enterprise architecture. The distinction between SA-17 and PL-8 is especially important when organizations outsource the development of systems, system components, or system services and when there is a requirement to demonstrate consistency with the enterprise architecture and security and privacy architecture of the organization. ISO 15408-2, ISO 15408-3 , and SP 800-160-1 provide information on security architecture and design, including formal policy models, security-relevant components, formal and informal correspondence, conceptually simple design, and structuring for least privilege and testing.
Assessment Objective: the developer of the system, system component, or system service is required to produce a design specification and security architecture that are consistent with the organization’s security architecture, which is an integral part the organization’s enterprise architecture;
Assessment Objective: the developer of the system, system component, or system service is required to produce a design specification and privacy architecture that are consistent with the organization’s privacy architecture, which is an integral part the organization’s enterprise architecture;
Assessment Objective: the developer of the system, system component, or system service is required to produce a design specification and security architecture that accurately and completely describe the required security functionality and the allocation of controls among physical and logical components;
Assessment Objective: the developer of the system, system component, or system service is required to produce a design specification and privacy architecture that accurately and completely describe the required privacy functionality and the allocation of controls among physical and logical components;
Assessment Objective: the developer of the system, system component, or system service is required to produce a design specification and security architecture that express how individual security functions, mechanisms, and services work together to provide required security capabilities and a unified approach to protection;
Assessment Objective: the developer of the system, system component, or system service is required to produce a design specification and privacy architecture that express how individual privacy functions, mechanisms, and services work together to provide required privacy capabilities and a unified approach to protection.
System and services acquisition policy
system and services acquisition procedures
enterprise architecture policy
enterprise architecture documentation
procedures addressing developer security and privacy architecture and design specifications for the system
solicitation documentation
acquisition documentation
service level agreements
acquisition contracts for the system, system component, or system service
system design documentation
information system configuration settings and associated documentation
system security plan
privacy plan
other relevant documents or records
Organizational personnel with acquisition responsibilities
organizational personnel with information security and privacy responsibilities
system developer