|
controlSA-3

System Development Life Cycle (SA-3)

Acquire, develop, and manage the system using [organization-defined] that incorporates information security and privacy considerations; Define and document information security and privacy roles and responsibilities throughout the system development life cycle; Identify individuals having information security and privacy roles and responsibilities; and Integrate the organizational information security and privacy risk management process into system development life cycle activities.

Security Baselines

LOWMODERATEHIGH
acquisitionsdlcservicessupply-chain

Why These Connect

Maps To5

These are equivalent or closely aligned requirements in other frameworks.

Baselined In3

This control is included in the linked security baseline (LOW, MODERATE, or HIGH).

Supports21

These related controls work together — a change to one may affect the others.

Enhances3

These enhancements add specific capabilities or refinements to the base control.

Cross-Framework Mappings(5)

ID.AM-08ID.AM-08Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.PS-06PR.PS-06Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20224 mappingsFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
ID.AM-08ID.AM-08Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.PS-06PR.PS-06Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5

Control Enhancements(3)