Skip to content

SA-3: System Development Life Cycle

An OSCAL Control

Statement

    • a.

      Acquire, develop, and manage the system using that incorporates information security and privacy considerations;

    • b.

      Define and document information security and privacy roles and responsibilities throughout the system development life cycle;

    • c.

      Identify individuals having information security and privacy roles and responsibilities; and

    • d.

      Integrate the organizational information security and privacy risk management process into system development life cycle activities.