Skip to content

SA-17: Developer Security and Privacy Architecture and Design

An OSCAL Control

Statement

    • Require the developer of the system, system component, or system service to produce a design specification and security and privacy architecture that:

      • a.

        Is consistent with the organization’s security and privacy architecture that is an integral part the organization’s enterprise architecture;

      • b.

        Accurately and completely describes the required security and privacy functionality, and the allocation of controls among physical and logical components; and

      • c.

        Expresses how individual security and privacy functions, mechanisms, and services work together to provide required security and privacy capabilities and a unified approach to protection.