Control Mapping Readerplace a control, see the map

NIST800-SA-11(2) SA-11(2) Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses

NIST800-SA-11(2) in NIST SP 800-53 Rev 5 (NIST SP 800-53 Rev 5, Release 5.2.0). All NIST SP 800-53 Rev 5 controls held. Open NIST SP 800-53 Rev 5 on the standards site.

The control as we hold it

SA-11(2) Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses. Require the developer of the system, system component, or system service to perform threat modeling and vulnerability analyses during development and the subsequent testing and evaluation of the system, component, or service that: (a) Uses the following contextual information: [Assignment: organization-defined information concerning impact, environment of operations, known or assumed threats, and acceptable risk levels]; (b) Employs the following tools and methods: [Assignment: organization-defined tools and methods]; (c) Conducts the modeling and analyses at the following level of rigor: [Assignment:.

Reviewed and closest counterparts in the other frameworks

We hold no cross-framework row for NIST800-SA-11(2) yet. The reviewed pairs page lists the released pairs and their coverage.

What an auditor commonly asks for

General guidance for this control area (domain: SA - System and Services Acquisition), in our words, not a statement of the standard and not binding on an assessor.

Buy the reviewed crosswalk pair Place your own control