SA-17(5)
SA-17(5): Conceptually Simple Design
The organization requires the developer of the information system, system component, or information system service to:
- (a): Design and structure the security-relevant hardware, software, and firmware to use a complete, conceptually simple protection mechanism with precisely defined semantics; and
- (b): Internally structure the security-relevant hardware, software, and firmware with specific regard for this mechanism.
Supplemental
CIA Levels | |
---|---|
Confidentiality | unknown |
Integrity | unknown |
Availability | unknown |
Overlays |
---|
None |
CSF Categories |
---|
None |