← SA-3

Manage Preproduction Environment

LOW MODERATE HIGH
1 Overlay 5 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Protect system preproduction environments commensurate with risk throughout the system development life cycle for the system, system component, or system service.

Discussion (NIST Supplemental Guidance)

The preproduction environment includes development, test, and integration environments. The program protection planning processes established by the Department of Defense are examples of managing the preproduction environment for defense contractors. Criticality analysis and the application of controls on developers also contribute to a more secure system development environment.

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for SA-3(1) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. system pre-production environments are protected commensurate with risk throughout the system development life cycle for the system, system component, or system service.

Examine

[SELECT FROM: System and services acquisition policy; procedures addressing the integration of security and supply chain risk management into the system development life cycle process; system development life cycle documentation; procedures addressing program protection planning; criticality analysis results; security and supply chain risk management strategy/program documentation; system security plan; supply chain risk management plan; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with security and system life cycle development responsibilities; organizational personnel with information security responsibilities].

Test

[SELECT FROM: Organizational processes for defining and documenting the system development life cycle; organizational processes for identifying system development life cycle roles and responsibilities; organizational process for integrating security risk management into the system development life cycle; mechanisms supporting and/or implementing the system development life cycle].

Overlays

Showing the OT/ICS overlay for the parent control SA-3 — see the SA-3(1) entries within each baseline below.

OT/ICS Overlay SP 800-82r3

NIST SP 800-82r3 Appendix F, Table 22. Blank baseline means the control/control enhancement is not selected in that initial OT baseline.

LOW

  • Base control: Included (matches standard baseline)

MODERATE

  • Base control: Included (matches standard baseline)

HIGH

  • Base control: Included (matches standard baseline)

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for SA-3(1). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • System and services acquisition policy
  • procedures addressing program protection planning
  • security and supply chain risk management strategy/program documentation
  • system security plan
  • supply chain risk management plan

Testing

  • Organizational processes for defining and documenting the system development life cycle
  • organizational processes for identifying system development life cycle roles and responsibilities
  • organizational process for integrating security risk management into the system development life cycle
  • mechanisms supporting and/or implementing the system development life cycle

Other Records

  • procedures addressing the integration of security and supply chain risk management into the system development life cycle process
  • system development life cycle documentation
  • criticality analysis results
  • other relevant documents or records