|
control enhancementSA-11(2)

Threat Modeling and Vulnerability Analyses (SA-11(2))

Require the developer of the system, system component, or system service to perform threat modeling and vulnerability analyses during development and the subsequent testing and evaluation of the system, component, or service that:

acquisitionsdlcservicessupply-chainenhancement

Why These Connect

Maps To2

These are equivalent or closely aligned requirements in other frameworks.

Enhances1

These enhancements add specific capabilities or refinements to the base control.

Cross-Framework Mappings(2)

ID.RA-01ID.RA-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ID.RA-01ID.RA-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5

Organization-Defined Parameters(6)

Assignmentorganization-defined information
Assignmentorganization-defined tools and methods
Assignmentorganization-defined breadth and depth
Assignmentorganization-defined breadth and depth
Assignmentorganization-defined acceptance criteria
Assignmentorganization-defined acceptance criteria