System Development Life Cycle (SA-3)
Acquire, develop, and manage the system using [organization-defined] that incorporates information security and privacy considerations; Define and document information security and privacy roles and responsibilities throughout the system development life cycle; Identify individuals having information security and privacy roles and responsibilities; and Integrate the organizational information security and privacy risk management process into system development life cycle activities.
Security Baselines
Why These Connect
These are equivalent or closely aligned requirements in other frameworks.
This control is included in the linked security baseline (LOW, MODERATE, or HIGH).
These related controls work together — a change to one may affect the others.
These enhancements add specific capabilities or refinements to the base control.