|
control enhancementSA-4(3)
Development Methods, Techniques, and Practices (SA-4(3))
Require the developer of the system, system component, or system service to demonstrate the use of a system development life cycle process that includes:
acquisitionsdlcservicessupply-chainenhancement
Why These Connect
Maps To1
These are equivalent or closely aligned requirements in other frameworks.
Enhances1
These enhancements add specific capabilities or refinements to the base control.
Cross-Framework Mappings(1)
ISO 27001ISO/IEC 27001:20221 mappingFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
Organization-Defined Parameters(8)
Assignmentorganization-defined systems engineering methods
SelectionSelection (one-or-more): {{ insert: param, sa-04.03_odp.03 }} / {{ insert: param, sa-04.03_odp.04 }}
Assignmentorganization-defined system security engineering methods
Assignmentorganization-defined privacy engineering methods
SelectionSelection (one-or-more): {{ insert: param, sa-04.03_odp.06 }} / {{ insert: param, sa-04.03_odp.07 }} / {{ insert: param, sa-04.03_odp.08 }}
Assignmentorganization-defined software development methods
Assignmentorganization-defined testing, evaluation, assessment, verification, and validation methods
Assignmentorganization-defined quality control processes