id: "SA-17(08)" title: "Orchestration" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-17.08" priority: "P1" implementation_level: "organization" parent: "SA-17" enhancement: True
Statement
Design {{ insert: param, sa-17.08_odp.01 }} with coordinated behavior to implement the following capabilities: {{ insert: param, sa-17.08_odp.02 }}.
Guidance
Security resources that are distributed, located at different layers or in different system elements, or are implemented to support different aspects of trustworthiness can interact in unforeseen or incorrect ways. Adverse consequences can include cascading failures, interference, or coverage gaps. Coordination of the behavior of security resources (e.g., by ensuring that one patch is installed across all resources before making a configuration change that assumes that the patch is propagated) can avert such negative interactions.
Assessment Objective
{{ insert: param, sa-17.08_odp.01 }} are designed with coordinated behavior to implement {{ insert: param, sa-17.08_odp.02 }}.
System and services acquisition policy
enterprise architecture policy
procedures addressing developer security and privacy architecture and design
enterprise architecture
security architecture
solicitation documentation
acquisition documentation
service level agreements
acquisition contracts for the system, system component, or system service
system design documentation
system configuration settings and associated documentation
developer documentation describing design orchestration
system security plan
privacy plan
other relevant documents or records
Organizational personnel with system and service acquisition responsibilities
organizational personnel with information security and privacy responsibilities
system developer
organizational personnel with information security architecture responsibilities