CCI-004815
CCI-004815 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if: - the developer of the system, system component, or system service is required to employ interactive application security testing tools to identify flaws. - the developer of the system, system component, or system service is required to document the results of flaw identification.
Validation Procedures
Examine: [SELECT FROM: System and services acquisition policy; procedures addressing system developer security testing; procedures addressing interactive application security testing; solicitation documentation; acquisition documentation; service level agreements; acquisition contracts for the system, system component, or system service; system developer security test and evaluation plans; security test and evaluation results; security flaw and remediation tracking reports; system security plan; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with system and service acquisition responsibilities; organizational personnel with information security responsibilities; organizational personnel with developer security testing responsibilities; organizational personnel with configuration management responsibilities; system developers]. Test: [SELECT FROM: Organizational processes for interactive application security testing; mechanisms supporting and/or implementing interactive application security testing].