id: "SA-17(02)" title: "Security-relevant Components" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-17.02" priority: "P1" implementation_level: "organization" parent: "SA-17" enhancement: True


Statement

Require the developer of the system, system component, or system service to:

Define security-relevant hardware, software, and firmware; and

Provide a rationale that the definition for security-relevant hardware, software, and firmware is complete.

Guidance

The security-relevant hardware, software, and firmware represent the portion of the system, component, or service that is trusted to perform correctly to maintain required security properties.

Assessment Objective: the developer of the system, system component, or system service is required to define security-relevant hardware;

Assessment Objective: the developer of the system, system component, or system service is required to define security-relevant software;

Assessment Objective: the developer of the system, system component, or system service is required to define security-relevant firmware;

Assessment Objective: the developer of the system, system component, or system service is required to provide a rationale that the definition for security-relevant hardware, software, and firmware is complete.

System and services acquisition policy

enterprise architecture policy

procedures addressing developer security architecture and design specifications for the system

solicitation documentation

acquisition documentation

service level agreements

acquisition contracts for the system, system component, or system service

list of security-relevant hardware, software, and firmware components

documented rationale of completeness regarding definitions provided for security-relevant hardware, software, and firmware

system security plan

other relevant documents or records

Organizational personnel with system and service acquisition responsibilities

organizational personnel with information security responsibilities

system developers

organizational personnel with information security architecture and design responsibilities