id: "SA-17(06)" title: "Structure for Testing" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-17.06" priority: "P1" implementation_level: "organization" parent: "SA-17" enhancement: True


Statement

Require the developer of the system, system component, or system service to structure security-relevant hardware, software, and firmware to facilitate testing.

Guidance

Applying the security design principles in SP 800-160-1 promotes complete, consistent, and comprehensive testing and evaluation of systems, system components, and services. The thoroughness of such testing contributes to the evidence produced to generate an effective assurance case or argument as to the trustworthiness of the system, system component, or service.

Assessment Objective

the developer of the system, system component, or system service is required to structure security-relevant hardware, software, and firmware to facilitate testing.

System and services acquisition policy

enterprise architecture policy

procedures addressing developer security architecture and design specifications for the system

solicitation documentation

acquisition documentation

service level agreements

acquisition contracts for the system, system component, or system service

system design documentation

system security architecture documentation

privacy architecture documentation

system configuration settings and associated documentation

developer documentation describing the design and structure of security-relevant hardware, software, and firmware components to facilitate testing

system security plan

privacy plan

other relevant documents or records

Organizational personnel with system and service acquisition responsibilities

organizational personnel with information security and privacy responsibilities

system developer

organizational personnel with information security and privacy architecture and design responsibilities