Manage Preproduction Environment
LOW MODERATE HIGHRequirements NIST SOURCE
Protect system preproduction environments commensurate with risk throughout the system development life cycle for the system, system component, or system service.
Discussion (NIST Supplemental Guidance)
The preproduction environment includes development, test, and integration environments. The program protection planning processes established by the Department of Defense are examples of managing the preproduction environment for defense contractors. Criticality analysis and the application of controls on developers also contribute to a more secure system development environment.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for SA-3(1) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- system pre-production environments are protected commensurate with risk throughout the system development life cycle for the system, system component, or system service.
Examine
[SELECT FROM: System and services acquisition policy; procedures addressing the integration of security and supply chain risk management into the system development life cycle process; system development life cycle documentation; procedures addressing program protection planning; criticality analysis results; security and supply chain risk management strategy/program documentation; system security plan; supply chain risk management plan; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with security and system life cycle development responsibilities; organizational personnel with information security responsibilities].
Test
[SELECT FROM: Organizational processes for defining and documenting the system development life cycle; organizational processes for identifying system development life cycle roles and responsibilities; organizational process for integrating security risk management into the system development life cycle; mechanisms supporting and/or implementing the system development life cycle].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for SA-3(1). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- System and services acquisition policy
- procedures addressing program protection planning
- security and supply chain risk management strategy/program documentation
- system security plan
- supply chain risk management plan
Testing
- Organizational processes for defining and documenting the system development life cycle
- organizational processes for identifying system development life cycle roles and responsibilities
- organizational process for integrating security risk management into the system development life cycle
- mechanisms supporting and/or implementing the system development life cycle
Other Records
- procedures addressing the integration of security and supply chain risk management into the system development life cycle process
- system development life cycle documentation
- criticality analysis results
- other relevant documents or records