CCI-004702
CCI-004702 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if the developer of the system, system component, or system service is required to demonstrate the use of a system development life cycle process that includes [SA-04(03)_ODP[05]; one or more of the following PARAMETER VALUES is/are selected: {[SA-04(03)_ODP[06]; software development methods are defined (if selected)]; [SA-04(03)_ODP[07]; testing, evaluation, assessment, verification, and validation methods are defined (if selected)]; [SA-04(03)_ODP[08]; quality control processes are defined (if selected)]}].
Validation Procedures
Examine: [SELECT FROM: System and services acquisition policy; system and services acquisition procedures; procedures addressing the integration of security and privacy requirements, descriptions, and criteria into the acquisition process; solicitation documents; acquisition documentation; acquisition contracts for the system, system component, or system service; list of systems security and privacy engineering methods to be included in the developerís system development life cycle process; list of software development methods to be included in the developerís system development life cycle process; list of testing, evaluation, or validation techniques to be included in the developerís system development life cycle process; list of quality control processes to be included in the developerís system development life cycle process; system security plan; privacy plan; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with acquisition/contracting responsibilities; organizational personnel with information security and privacy responsibilities; organizational personnel with system life cycle responsibilities; system developers or service provider]. Test: [SELECT FROM: Organizational processes for development methods, techniques, and processes].