id: "SA-17(02)" title: "Security-relevant Components" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-17.02" priority: "P1" implementation_level: "organization" parent: "SA-17" enhancement: True
Statement
Require the developer of the system, system component, or system service to:
Define security-relevant hardware, software, and firmware; and
Provide a rationale that the definition for security-relevant hardware, software, and firmware is complete.
Guidance
The security-relevant hardware, software, and firmware represent the portion of the system, component, or service that is trusted to perform correctly to maintain required security properties.
Assessment Objective: the developer of the system, system component, or system service is required to define security-relevant hardware;
Assessment Objective: the developer of the system, system component, or system service is required to define security-relevant software;
Assessment Objective: the developer of the system, system component, or system service is required to define security-relevant firmware;
Assessment Objective: the developer of the system, system component, or system service is required to provide a rationale that the definition for security-relevant hardware, software, and firmware is complete.
System and services acquisition policy
enterprise architecture policy
procedures addressing developer security architecture and design specifications for the system
solicitation documentation
acquisition documentation
service level agreements
acquisition contracts for the system, system component, or system service
list of security-relevant hardware, software, and firmware components
documented rationale of completeness regarding definitions provided for security-relevant hardware, software, and firmware
system security plan
other relevant documents or records
Organizational personnel with system and service acquisition responsibilities
organizational personnel with information security responsibilities
system developers
organizational personnel with information security architecture and design responsibilities