System Development Life Cycle

✓ LOW ✓ MODERATE ✓ HIGH
3 Enhancements 1 Overlay 14 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Discussion (NIST Supplemental Guidance)

A system development life cycle process provides the foundation for the successful development, implementation, and operation of organizational systems. The integration of security and privacy considerations early in the system development life cycle is a foundational principle of systems security engineering and privacy engineering. To apply the required controls within the system development life cycle requires a basic understanding of information security and privacy, threats, vulnerabilities, adverse impacts, and risk to critical mission and business functions. The security engineering principles in SA-8 help individuals properly design, code, and test systems and system components. Organizations include qualified personnel (e.g., senior agency information security officers, senior agency officials for privacy, security and privacy architects, and security and privacy engineers) in system development life cycle processes to ensure that established security and privacy requirements are incorporated into organizational systems. Role-based security and privacy training programs can ensure that individuals with key security and privacy roles and responsibilities have the experience, skills, and expertise to conduct assigned system development life cycle activities. The effective integration of security and privacy requirements into enterprise architecture also helps to ensure that important security and privacy considerations are addressed throughout the system life cycle and that those considerations are directly related to organizational mission and business processes. This process also facilitates the integration of the information security and privacy architectures into the enterprise architecture, consistent with the risk management strategy of the organization. Because the system development life cycle involves multiple organizations, (e.g., external suppliers, developers, integrators, service providers), acquisition and supply chain risk management functions and controls play significant roles in the effective management of the system during the life cycle.

Enhancements NIST SOURCE

SA-3(1) Manage Preproduction Environment LOW MODERATE HIGH

Protect system preproduction environments commensurate with risk throughout the system development life cycle for the system, system component, or system service.

Discussion

The preproduction environment includes development, test, and integration environments. The program protection planning processes established by the Department of Defense are examples of managing the preproduction environment for defense contractors. Criticality analysis and the application of controls on developers also contribute to a more secure system development environment.

Open full page for SA-3(1) →
SA-3(2) Use of Live or Operational Data LOW MODERATE HIGH
  1. (a) Approve, document, and control the use of live data in preproduction environments for the system, system component, or system service; and
  2. (b) Protect preproduction environments for the system, system component, or system service at the same impact or classification level as any live data in use within the preproduction environments.
Discussion

Live data is also referred to as operational data. The use of live or operational data in preproduction (i.e., development, test, and integration) environments can result in significant risks to organizations. In addition, the use of personally identifiable information in testing, research, and training increases the risk of unauthorized disclosure or misuse of such information. Therefore, it is important for the organization to manage any additional risks that may result from the use of live or operational data. Organizations can minimize such risks by using test or dummy data during the design, development, and testing of systems, system components, and system services. Risk assessment techniques may be used to determine if the risk of using live or operational data is acceptable.

Open full page for SA-3(2) →
SA-3(3) Technology Refresh LOW MODERATE HIGH

Plan for and implement a technology refresh schedule for the system throughout the system development life cycle.

Discussion

Technology refresh planning may encompass hardware, software, firmware, processes, personnel skill sets, suppliers, service providers, and facilities. The use of obsolete or nearing obsolete technology may increase the security and privacy risks associated with unsupported components, counterfeit or repurposed components, components unable to implement security or privacy requirements, slow or inoperable components, components from untrusted sources, inadvertent personnel error, or increased complexity. Technology refreshes typically occur during the operations and maintenance stage of the system development life cycle.

Open full page for SA-3(3) →

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for SA-3 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. system development life cycle is defined;
  2. the system is acquired, developed, and managed using <SA-03_ODP system-development life cycle> that incorporates information security considerations;
  3. the system is acquired, developed, and managed using <SA-03_ODP system-development life cycle> that incorporates privacy considerations;
  4. information security roles and responsibilities are defined and documented throughout the system development life cycle;
  5. privacy roles and responsibilities are defined and documented throughout the system development life cycle;
  6. individuals with information security roles and responsibilities are identified;
  7. individuals with privacy roles and responsibilities are identified;
  8. organizational information security risk management processes are integrated into system development life cycle activities;
  9. organizational privacy risk management processes are integrated into system development life cycle activities.

Examine

[SELECT FROM: System and services acquisition policy; system and services acquisition procedures; procedures addressing the integration of information security and privacy and supply chain risk management into the system development life cycle process; system development life cycle documentation; organizational risk management strategy; information security and privacy risk management strategy documentation; system security plan; privacy plan; privacy program plan; enterprise architecture documentation; role-based security and privacy training program documentation; data mapping documentation; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with information security and privacy responsibilities; organizational personnel with system life cycle development responsibilities; organizational personnel with supply chain risk management responsibilities].

Test

[SELECT FROM: Organizational processes for defining and documenting the system development life cycle; organizational processes for identifying system development life cycle roles and responsibilities; organizational processes for integrating information security and privacy and supply chain risk management into the system development life cycle; mechanisms supporting and/or implementing the system development life cycle].

Overlays

OT/ICS Overlay SP 800-82r3

NIST SP 800-82r3 Appendix F, Table 22. Blank baseline means the control/control enhancement is not selected in that initial OT baseline.

LOW

  • Base control: Included (matches standard baseline)

MODERATE

  • Base control: Included (matches standard baseline)

HIGH

  • Base control: Included (matches standard baseline)

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for SA-3. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • System and services acquisition policy
  • organizational risk management strategy
  • information security and privacy risk management strategy documentation
  • system security plan
  • privacy plan
  • privacy program plan
  • role-based security and privacy training program documentation

Configuration

  • enterprise architecture documentation

Testing

  • Organizational processes for defining and documenting the system development life cycle
  • organizational processes for identifying system development life cycle roles and responsibilities
  • organizational processes for integrating information security and privacy and supply chain risk management into the system development life cycle
  • mechanisms supporting and/or implementing the system development life cycle

Other Records

  • system and services acquisition procedures
  • procedures addressing the integration of information security and privacy and supply chain risk management into the system development life cycle process
  • system development life cycle documentation
  • data mapping documentation
  • other relevant documents or records