|
controlSA-15

Development Process, Standards, and Tools (SA-15)

Require the developer of the system, system component, or system service to follow a documented development process that: Review the development process, standards, tools, tool options, and tool configurations [organization-defined] to determine if the process, standards, tools, tool options and tool configurations selected and employed can satisfy the following security and privacy requirements: [organization-defined].

Security Baselines

MODERATEHIGHLOW
acquisitionsdlcservicessupply-chain

Why These Connect

Maps To5

These are equivalent or closely aligned requirements in other frameworks.

Baselined In2

This control is included in the linked security baseline (LOW, MODERATE, or HIGH).

Supports35

These related controls work together — a change to one may affect the others.

Enhances13

These enhancements add specific capabilities or refinements to the base control.

Cross-Framework Mappings(5)

ID.RA-09ID.RA-09Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.PS-06PR.PS-06Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20223 mappingsFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
ID.RA-09ID.RA-09Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.PS-06PR.PS-06Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5

Organization-Defined Parameters(3)

Assignmentorganization-defined frequency
Assignmentorganization-defined security requirements
Assignmentorganization-defined privacy requirements

Control Enhancements(13)