CCI-004843
      
        
        
      
      
        
  CCI-004843 Definition
      
      
        
        
      
    
  | Status | |
| Type | CheckType.policy | 
      
        
        
      
      
        
  Master Assessment Datasheet
      
      
        
        
      
    
  Implementation Guidance
Determine if: - as an integral part of the development process, the developer of the system, system component, or system service is required to produce a formal policy model describing the [SA-17(01)_ODP[01]; organizational security policy to be enforced is defined] to be enforced. - as an integral part of the development process, the developer of the system, system component, or system service is required to produce a formal policy model describing the [SA-17(01)_ODP[02]; organizational privacy policy to be enforced is defined] to be enforced.
Validation Procedures
Examine: [SELECT FROM: System and services acquisition policy; system and services acquisition procedures; enterprise architecture policy; enterprise architecture documentation; procedures addressing developer security and privacy architecture and design specifications for the system; solicitation documentation; acquisition documentation; service level agreements; acquisition contracts for the system, system component, or system service; system design documentation; system configuration settings and associated documentation; system security plan; privacy plan; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with acquisition responsibilities; organizational personnel with information security and privacy responsibilities; system developer].