STIGhub
STIGs
RMF Controls
Compare
← All Controls
SA-15
System and Services Acquisition
Rev 5
Development Process, Standards, and Tools
CCI Identifiers (21)
CCI-003233
Require the developer of the system, system component, or system service to follow a documented development process.
CCI-003234
Require the developer of the system, system component, or system service to follow a documented development process that explicitly addresses security requirements.
CCI-003235
Require the developer of the system, system component, or system service to follow a documented development process that identifies the standards used in the development process.
CCI-003236
Require the developer of the system, system component, or system service to follow a documented development process that identifies the tools used in the development process.
CCI-003237
Require the developer of the system, system component, or system service to follow a documented development process that documents the specific tool options and tool configurations used in the development process.
CCI-003238
Require the developer of the system, system component, or system service to follow a documented development process that documents changes to the process and/or tools used in development.
CCI-003239
Require the developer of the system, system component, or system service to follow a documented development process that manages changes to the process and/or tools used in development.
CCI-003240
Require the developer of the system, system component, or system service to follow a documented development process that ensures the integrity of changes to the process and/or tools used in development.
CCI-003241
Review the development process in accordance with organization-defined frequency to determine if the development process selected and employed can satisfy organization-defined security requirements.
CCI-003242
Review the development standards in accordance with organization-defined frequency to determine if the development standards selected and employed can satisfy organization-defined security requirements.
CCI-003243
Review the development tools in accordance with organization-defined frequency to determine if the development tools selected and employed can satisfy organization-defined security requirements.
CCI-003244
Review the development tool options/configurations in accordance with organization-defined frequency to determine if the development tool options and tool configurations selected and employed can satisfy organization-defined security requirements.
CCI-003245
Defines the frequency on which to review the development process, standards, tools, and tool options/configurations to determine if the process, standards, tools, and tool options and tool configurations selected and employed can satisfy organization-defined security requirements.
CCI-003246
Defines the security requirements that must be satisfied by conducting a review of the development process, standards, tools, and tool options and tool configurations.
CCI-004816
Require the developer of the system, system component, or system service to follow a documented development process that explicitly addresses privacy requirements.
CCI-004817
Review the development process in accordance with organization-defined frequency to determine if the development process selected and employed can satisfy organization-defined privacy requirements.
CCI-004818
Review the development standards in accordance with organization-defined frequency to determine if the development standards selected and employed can satisfy organization-defined privacy requirements.
CCI-004819
Review the development tools in accordance with organization-defined frequency to determine if the development tools selected and employed can satisfy organization-defined privacy requirements.
CCI-004820
Review the development tool options/configurations in accordance with organization-defined frequency to determine if the development tool options and tool configurations selected and employed can satisfy organization-defined privacy requirements.
CCI-004821
Defines the frequency on which to review the development process, standards, tools, and tool options/configurations to determine if the process, standards, tools, and tool options and tool configurations selected and employed can satisfy organization-defined privacy requirements.
CCI-004822
Defines the privacy requirements that must be satisfied by conducting a review of the development process, standards, tools, and tool options and tool configurations.
Linked STIG Checks (2)
Across 1 STIGs. Click to expand.
▶
Application Security and Development Security Technical Implementation Guide
2 checks