SA-15—Development Process, Standards, and Tools
>Control Description
Require the developer of the system, system component, or system service to follow a documented development process that:
Explicitly addresses security and privacy requirements;
Identifies the standards and tools used in the development process;
Documents the specific tool options and tool configurations used in the development process; and
Documents, manages, and ensures the integrity of changes to the process and/or tools used in development; and
Review the development process, standards, tools, tool options, and tool configurations ⚙organization-defined frequency to determine if the process, standards, tools, tool options and tool configurations selected and employed can satisfy the following security and privacy requirements: ⚙organization-defined security and privacy requirements.
>Related Controls
Ask AI
Configure your API key to use AI features.