id: "SR-09(01)" title: "Multiple Stages of System Development Life Cycle" family: "SR" family_name: "Supply Chain Risk Management" sort_id: "sr-09.01" priority: "P1" implementation_level: "organization" parent: "SR-09" enhancement: True


Statement

Employ anti-tamper technologies, tools, and techniques throughout the system development life cycle.

Guidance

The system development life cycle includes research and development, design, manufacturing, acquisition, delivery, integration, operations and maintenance, and disposal. Organizations use a combination of hardware and software techniques for tamper resistance and detection. Organizations use obfuscation and self-checking to make reverse engineering and modifications more difficult, time-consuming, and expensive for adversaries. The customization of systems and system components can make substitutions easier to detect and therefore limit damage.

Assessment Objective

anti-tamper technologies, tools, and techniques are employed throughout the system development life cycle.

Supply chain risk management policy and procedures

supply chain risk management plan

system and services acquisition policy

procedures addressing tamper resistance and detection

tamper protection program documentation

tamper protection tools and techniques documentation

tamper resistance and detection tools (technologies) and techniques documentation

system development life cycle documentation

procedures addressing supply chain protection

system development life cycle procedures

acquisition documentation

service level agreements

acquisition contracts for the system, system component, or system service

inter-organizational agreements and procedures

system security plan

other relevant documents or records

Organizational personnel with system and services acquisition responsibilities

organizational personnel with information security responsibilities

organizational personnel with supply chain risk management responsibilities

organizational personnel with SDLC responsibilities

Organizational processes for employing anti-tamper technologies

mechanisms supporting and/or implementing anti-tamper technologies