NIST800-SA-17(1) SA-17(1) Developer Security and Privacy Architecture and Design | Formal Policy Model
NIST800-SA-17(1) in NIST SP 800-53 Rev 5 (NIST SP 800-53 Rev 5, Release 5.2.0). All NIST SP 800-53 Rev 5 controls held. Open NIST SP 800-53 Rev 5 on the standards site.
The control as we hold it
SA-17(1) Developer Security and Privacy Architecture and Design | Formal Policy Model. Require the developer of the system, system component, or system service to: (a) Produce, as an integral part of the development process, a formal policy model describing the [Assignment: organization-defined elements of organizational security and privacy policy] to be enforced; and (b) Prove that the formal policy model is internally consistent and sufficient to enforce the defined elements of the organizational security and privacy policy when implemented.
Reviewed and closest counterparts in the other frameworks
We hold no cross-framework row for NIST800-SA-17(1) yet. The reviewed pairs page lists the released pairs and their coverage.
What an auditor commonly asks for
General guidance for this control area (domain: SA - System and Services Acquisition), in our words, not a statement of the standard and not binding on an assessor.
- the acquisition policy
- the security-requirement records
- the developer and supply-chain records