STIGhub
STIGs
RMF Controls
Compare
← All Controls
SA-11
System and Services Acquisition
Rev 3
Developer Testing and Evaluation
CCI Identifiers (21)
CCI-000702
The organization requires information system developers, in consultation with associated security personnel (including security engineers), to create a security test and evaluation plan.
CCI-000703
The organization requires information system developers, in consultation with associated security personnel (including security engineers), to implement a security test and evaluation plan.
CCI-000704
The organization requires information system integrators, in consultation with associated security personnel (including security engineers), to create a security test and evaluation plan.
CCI-000705
The organization requires information system integrators, in consultation with associated security personnel (including security engineers), to implement a security test and evaluation plan.
CCI-000706
The organization requires information system developers, in consultation with associated security personnel (including security engineers), to implement a verifiable flaw remediation process to correct weaknesses and deficiencies identified during the security testing and evaluation process.
CCI-000707
The organization requires information system integrators, in consultation with associated security personnel (including security engineers), to implement a verifiable flaw remediation process to correct weaknesses and deficiencies identified during the security testing and evaluation process.
CCI-000708
The organization requires information system developers, in consultation with associated security personnel (including security engineers), to document the results of the security testing/evaluation processes.
CCI-000709
The organization requires information system developers, in consultation with associated security personnel (including security engineers), to document the results of the security flaw remediation processes.
CCI-000710
The organization requires information system integrators, in consultation with associated security personnel (including security engineers), to document the results of the security testing/evaluation processes.
CCI-000711
The organization requires information system integrators, in consultation with associated security personnel (including security engineers), to document the results of the security flaw remediation processes.
CCI-003171
Require the developer of the system, system component, or system service, at all post-design phases of the system development life cycle, to develop a plan for ongoing security control assessment.
CCI-003172
Require the developer of the system, system component, or system service to implement a plan for ongoing security control assessment.
CCI-003173
Requires the developer of the system, system component, or system service, at all post-design phases of the system development life cycle, to perform unit, integration, system, and/or regression testing/evaluation on an organization-defined frequency, at an organization-defined depth and coverage.
CCI-003174
Defines the depth and coverage at which to perform unit, integration, system, and/or regression testing/evaluation on an organization-defined frequency.
CCI-003175
Requires the developer of the system, system component, or system service, at all post-design phases of the system development life cycle, to produce evidence of the execution of the assessment plan.
CCI-003176
Requires the developer of the system, system component, or system service, at all post-design phases of the system development life cycle, to produce the results of the testing and evaluation.
CCI-003177
Requires the developer of the system, system component, or system service, at all post-design phases of the system development life cycle, to implement a verifiable flaw remediation process.
CCI-003178
Requires the developer of the system, system component, or system service, at all post-design phases of the system development life cycle, to correct flaws identified during testing/evaluation.
CCI-004798
Require the developer of the system, system component, or system service, at all post-design phases of the system development life cycle, to develop a plan for ongoing privacy control assessment.
CCI-004799
Require the developer of the system, system component, or system service to implement a plan for ongoing privacy control assessment.
CCI-004800
Defines the frequency that the unit, integration, system, and/or regression testing/evaluation is performed at an organization-defined depth and coverage.
Linked STIG Checks (3)
Across 1 STIGs. Click to expand.
▶
Application Security and Development Security Technical Implementation Guide
3 checks