CCI-004800
CCI-004800 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if the developer of the system, system component, or system service is required at all post-design stages of the system development life cycle to perform [SA-11_ODP[01]; one or more of the following PARAMETER VALUES is/are selected: {unit; integration; system; regression}] testing/evaluation [SA-11_ODP[02]; frequency at which to conduct [SA-11_ODP[01]; one or more of the following PARAMETER VALUES is/are selected: {unit; integration; system; regression}] testing/evaluation is defined] at [SA-11_ODP[03]; depth and coverage of [SA-11_ODP[01]; one or more of the following PARAMETER VALUES is/are selected: {unit; integration; system; regression}] testing/evaluation is defined].
Validation Procedures
Examine: [SELECT FROM: System and services acquisition policy; system and services acquisition procedures; procedures addressing system developer security and privacy testing; procedures addressing flaw remediation; solicitation documentation; acquisition documentation; service level agreements; acquisition contracts for the system, system component, or system service; security and privacy architecture; system design documentation; system developer security and privacy assessment plans; results of developer security and privacy assessments for the system, system component, or system service; security and privacy flaw and remediation tracking records; system security plan; privacy plan; privacy impact assessment; privacy risk assessment documentation; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with system and service acquisition responsibilities; organizational personnel with information security and privacy responsibilities; organizational personnel with developer security and privacy testing responsibilities; system developers]. Test: [SELECT FROM: Organizational processes for monitoring developer security testing and evaluation; mechanisms supporting and/or implementing the monitoring of developer security and privacy testing and evaluation].