id: "SA-17(08)" title: "Orchestration" family: "SA" family_name: "System and Services Acquisition" sort_id: "sa-17.08" priority: "P1" implementation_level: "organization" parent: "SA-17" enhancement: True


Statement

Design {{ insert: param, sa-17.08_odp.01 }} with coordinated behavior to implement the following capabilities: {{ insert: param, sa-17.08_odp.02 }}.

Guidance

Security resources that are distributed, located at different layers or in different system elements, or are implemented to support different aspects of trustworthiness can interact in unforeseen or incorrect ways. Adverse consequences can include cascading failures, interference, or coverage gaps. Coordination of the behavior of security resources (e.g., by ensuring that one patch is installed across all resources before making a configuration change that assumes that the patch is propagated) can avert such negative interactions.

Assessment Objective

{{ insert: param, sa-17.08_odp.01 }} are designed with coordinated behavior to implement {{ insert: param, sa-17.08_odp.02 }}.

System and services acquisition policy

enterprise architecture policy

procedures addressing developer security and privacy architecture and design

enterprise architecture

security architecture

solicitation documentation

acquisition documentation

service level agreements

acquisition contracts for the system, system component, or system service

system design documentation

system configuration settings and associated documentation

developer documentation describing design orchestration

system security plan

privacy plan

other relevant documents or records

Organizational personnel with system and service acquisition responsibilities

organizational personnel with information security and privacy responsibilities

system developer

organizational personnel with information security architecture responsibilities