STIGhub
STIGs
RMF Controls
Compare
← All Controls
SA-17
System and Services Acquisition
Rev 5
Developer Security and Privacy Architecture and Design
CCI Identifiers (10)
CCI-003293
Require the developer of the system, system component, or system service to produce a design specification and security architecture.
CCI-003294
Require the developer of the system, system component, or system service to produce a design specification and security architecture that is consistent with and supportive of the organization's security architecture which is established within and is an integrated part of the organization's enterprise architecture.
CCI-003295
Require the developer of the system, system component, or system service to produce a design specification and security architecture that accurately and completely describes the required security functionality.
CCI-003296
Require the developer of the system, system component, or system service to produce a design specification and security architecture that accurately and completely describes the allocation of security controls among physical and logical components.
CCI-003297
Require the developer of the system, system component, or system service to produce a design specification and security architecture that expresses how individual security functions, mechanisms, and services work together to provide required security capabilities and a unified approach to protection.
CCI-004837
Require the developer of the system, system component, or system service to produce a privacy architecture.
CCI-004838
Require the developer of the system, system component, or system service to produce a privacy architecture that is consistent with and supportive of the organization's privacy architecture which is established within and is an integrated part of the organization's enterprise architecture.
CCI-004839
Require the developer of the system, system component, or system service to produce a privacy architecture that accurately and completely describes the required privacy functionality.
CCI-004840
Require the developer of the system, system component, or system service to produce a privacy architecture that accurately and completely describes the allocation of privacy controls among physical and logical components.
CCI-004841
Require the developer of the system, system component, or system service to produce a privacy architecture that expresses how individual privacy functions, mechanisms, and services work together to provide required privacy capabilities and a unified approach to protection.
Linked STIG Checks (0)
No STIG checks reference this control.