CCI-003182
CCI-003182 Definition
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed requires within contracts/agreements that the developer the information system, system component, or information system service perform testing/evaluation of the as-built system, component, or service based on threat and vulnerability analysis.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the contracts/agreements to ensure the organization being inspected/assessed requires that the developer of the information system, system component, or information system service perform testing/evaluation of the as-built system, component, or service subsequent to threat and vulnerability analysis.
Compelling Evidence
1.) System security plan (SSP). 2.) System development life cycle (SDLC) documentation must require developer to perform testing/evaluation of the as-built system, component, or service subsequent to threat and vulnerability analysis.