{"data":{"id":"SA-11","name":"Developer Testing and Evaluation","family":"SA","family_name":"System and Services Acquisition","withdrawn":false,"description":"Require the developer of the system, system component, or system service, at all post-design stages of the system development life cycle, to:\na. Develop and implement a plan for ongoing security and privacy control assessments;\nb. Perform [Selection (one or more): unit; integration; system; regression] testing/evaluation [Assignment: organization-defined frequency] at [Assignment: organization-defined depth and coverage];\nc. Produce evidence of the execution of the assessment plan and the results of the testing and evaluation;\nd. Implement a verifiable flaw remediation process; and\ne. Correct flaws identified during testing and evaluation.","supplemental_guidance":"Developmental testing and evaluation confirms that the required controls are implemented correctly, operating as intended, enforcing the desired security and privacy policies, and meeting established security and privacy requirements. Security properties of systems and the privacy of individuals may be affected by the interconnection of system components or changes to those components. The interconnections or changes—including upgrading or replacing applications, operating systems, and firmware—may adversely affect previously implemented controls. Ongoing assessment during development allows for additional types of testing and evaluation that developers can conduct to reduce or eliminate potential flaws. Testing custom software applications may require approaches such as manual code review, security architecture review, and penetration testing, as well as and static analysis, dynamic analysis, binary analysis, or a hybrid of the three analysis approaches.\n\nDevelopers can use the analysis approaches, along with security instrumentation and fuzzing, in a variety of tools and in source code reviews. The security and privacy assessment plans include the specific activities that developers plan to carry out, including the types of analyses, testing, evaluation, and reviews of software and firmware components; the degree of rigor to be applied; the frequency of the ongoing testing and evaluation; and the types of artifacts produced during those processes. The depth of testing and evaluation refers to the rigor and level of detail associated with the assessment process. The coverage of testing and evaluation refers to the scope (i.e., number and type) of the artifacts included in the assessment process. Contracts specify the acceptance criteria for security and privacy assessment plans, flaw remediation processes, and the evidence that the plans and processes have been diligently applied. Methods for reviewing and protecting assessment plans, evidence, and documentation are commensurate with the security category or classification level of the system. Contracts may specify protection requirements for documentation.","enhancements":[{"id":"SA-11(01)","name":"Static Code Analysis","statement":"Require the developer of the system, system component, or system service to employ static code analysis tools to identify common flaws and document the results of the analysis.","baselines":[]},{"id":"SA-11(02)","name":"Threat Modeling and Vulnerability Analyses","statement":"Require the developer of the system, system component, or system service to perform threat modeling and vulnerability analyses during development and the subsequent testing and evaluation of the system, component, or service that:\na. Uses the following contextual information: [Assignment: organization-defined information concerning impact, environment of operations, known or assumed threats, and acceptable risk levels];\nb. Employs the following tools and methods: [Assignment: organization-defined tools and methods];\nc. Conducts the modeling and analyses at the following level of rigor: [Assignment: organization-defined breadth and depth of modeling and analyses]; and\nd. Produces evidence that meets the following acceptance criteria: [Assignment: organization-defined acceptance criteria].","baselines":[]},{"id":"SA-11(03)","name":"Independent Verification of Assessment Plans and Evidence","statement":"a. Require an independent agent satisfying [Assignment: organization-defined independence criteria] to verify the correct implementation of the developer security and privacy assessment plans and the evidence produced during testing and evaluation; and\nb. Verify that the independent agent is provided with sufficient information to complete the verification process or granted the authority to obtain such information.","baselines":[]},{"id":"SA-11(04)","name":"Manual Code Reviews","statement":"Require the developer of the system, system component, or system service to perform a manual code review of [Assignment: organization-defined specific code] using the following processes, procedures, and/or techniques: [Assignment: organization-defined processes, procedures, and/or techniques].","baselines":[]},{"id":"SA-11(05)","name":"Penetration Testing","statement":"Require the developer of the system, system component, or system service to perform penetration testing:\na. At the following level of rigor: [Assignment: organization-defined breadth and depth of testing]; and\nb. Under the following constraints: [Assignment: organization-defined constraints].","baselines":[]},{"id":"SA-11(06)","name":"Attack Surface Reviews","statement":"Require the developer of the system, system component, or system service to perform attack surface reviews.","baselines":[]},{"id":"SA-11(07)","name":"Verify Scope of Testing and Evaluation","statement":"Require the developer of the system, system component, or system service to verify that the scope of testing and evaluation provides complete coverage of the required controls at the following level of rigor: [Assignment: organization-defined breadth and depth of testing and evaluation].","baselines":[]},{"id":"SA-11(08)","name":"Dynamic Code Analysis","statement":"Require the developer of the system, system component, or system service to employ dynamic code analysis tools to identify common flaws and document the results of the analysis.","baselines":[]},{"id":"SA-11(09)","name":"Interactive Application Security Testing","statement":"Require the developer of the system, system component, or system service to employ interactive application security testing tools to identify flaws and document the results.","baselines":[]}],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"SA-11","name":"Developer Testing and Evaluation","description":"Require the developer of the system, system component, or system service, at all post-design stages of the system development life cycle, to:\na. Develop and implement a plan for ongoing security and privacy control assessments;\nb. Perform [Selection (one or more): unit; integration; system; regression] testing/evaluation [Assignment: organization-defined frequency] at [Assignment: organization-defined depth and coverage];\nc. Produce evidence of the execution of the assessment plan and the results of the testing and evaluation;\nd. Implement a verifiable flaw remediation process; and\ne. Correct flaws identified during testing and evaluation.","discussion":"Developmental testing and evaluation confirms that the required controls are implemented correctly, operating as intended, enforcing the desired security and privacy policies, and meeting established security and privacy requirements. Security properties of systems and the privacy of individuals may be affected by the interconnection of system components or changes to those components. The interconnections or changes—including upgrading or replacing applications, operating systems, and firmware—may adversely affect previously implemented controls. Ongoing assessment during development allows for additional types of testing and evaluation that developers can conduct to reduce or eliminate potential flaws. Testing custom software applications may require approaches such as manual code review, security architecture review, and penetration testing, as well as and static analysis, dynamic analysis, binary analysis, or a hybrid of the three analysis approaches.\n\nDevelopers can use the analysis approaches, along with security instrumentation and fuzzing, in a variety of tools and in source code reviews. The security and privacy assessment plans include the specific activities that developers plan to carry out, including the types of analyses, testing, evaluation, and reviews of software and firmware components; the degree of rigor to be applied; the frequency of the ongoing testing and evaluation; and the types of artifacts produced during those processes. The depth of testing and evaluation refers to the rigor and level of detail associated with the assessment process. The coverage of testing and evaluation refers to the scope (i.e., number and type) of the artifacts included in the assessment process. Contracts specify the acceptance criteria for security and privacy assessment plans, flaw remediation processes, and the evidence that the plans and processes have been diligently applied. Methods for reviewing and protecting assessment plans, evidence, and documentation are commensurate with the security category or classification level of the system. Contracts may specify protection requirements for documentation.","related_controls":["CA-02","CA-07","CM-04","SA-03","SA-04","SA-05","SA-08","SA-15","SA-17","SI-02","SR-05","SR-06","SR-07"],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":true,"new_in_rev5":false,"changes_from_rev4":"Title changed from 'Developer Security Testing and Evaluation' Control text adds 'ongoing' and  'privacy'   New parameter to specify frequency Discussion expanded to include privacy considerations"}},"compliance_mappings":{"iso_27001_2022":["A.8.25","A.8.28","A.8.29","A.8.30","A.8.31","A.8.33"],"iso_27002_2022":["8.25","8.26","8.28","8.29","8.30","8.31","8.33"],"cobit_2019":["APO11","BAI03","BAI07"],"pci_dss_v4":["6.2","6.2.3","6.4"],"nist_csf_2":["ID.IM-01","ID.IM-02","ID.IM-03","ID.RA-09","PR.PS-06"],"cis_controls_v8":["CIS 16","CIS 16.2","CIS 16.3","CIS 16.8","CIS 16.12","CIS 16.13"],"soc2_tsc":["CC4.1-POF1"],"finos_ccc":[],"iso_42001_2023":["A.6.2.4"],"iec_62443":[],"asd_e8":[],"nis2":["Art. 21(2)(e)"],"apra_cps_234":[],"mas_trm":["6"],"pra_op_resilience":[],"bsi_grundschutz":["APP.3.1","OPS.1.1.6"],"anssi":["Hygiene.31","Hygiene.33","SecNumCloud.15.5"],"osfi_b13":["B-13.3.2","B-13.3.5"],"finma_circular":["IV.A(36)","IV.A(37)","IV.D(75)","IV.D(76)"],"gdpr":["Art.25(1)","Art.32(1)(d)"],"dora":["Art.9(4)(e)","Art.25(1)","Art.25(2)"],"bio2":["8.25","8.26","8.28","8.29","8.30","8.31","8.33"],"rbi_csf":["Annex1.6","Annex1.18"],"fisc":["FISC.O10","FISC.T6"],"lgpd_bcb":["BCB.Art.10"],"hkma_tme1":["TME1.3.2","TME1.3.3"],"mlps_2":["8.1.9.4","8.1.9.5"],"dnb_good_practice":["DNB.10.3","DNB.10.4","DNB.22.1"],"cra":["CRA.I.1","CRA.I.2a","CRA.II.2","CRA.II.3"],"swift_cscf":["SWIFT.2.10"],"cbb_tm":["TM-7"],"cbuae":["CR-6"],"nca_ecc":["1-6","2-3","2-10","2-11","2-14"],"qatar_nia":["SD"],"sama_csf":["3.2"],"uae_ia":["T7","T10"],"bog_cisd":["CISD-IX","CISD-SDLC"],"bom_ctrm":["3.11"],"cbe_csf":["CTO-4"],"cbn_csf":["Part5.2"],"sa_js2":["JS2-7.7","JS2-SA"],"bcbs_239":["Principle 3","Principle 7"],"bot_cyber":["Ch2.5"],"cpmi_pfmi":["CG.TE","PFMI.P17"],"eba_ict":["3.4.6","3.6.2"],"ecb_croe":["CROE.2.3.4","CROE.2.6.1"],"ffiec_is":["II.C.15(b)","II.C.17","IV.A","IV.A.2"],"iosco_cyber":["PROT-6","SA-3","TEST-1","TEST-3"],"nydfs_500":["500.5","500.8"],"sebi_cscrf":["PR.AS","PR.IP"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":["SD-2 Sec G"],"ieee_1686":["5.10"],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":["F"],"fips_140":["FIPS 140-3 §7.5","FIPS 140-3 §7.11","FIPS 140-3 §7.12"],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":["CC Part 2 — FPT","CC Part 3 — SAR","CEM"],"isae_3402":["Clause 4"],"fca_sysc_13":["SYSC 13.7.1","SYSC 13.7.4"],"fda_21_cfr_11":["§11.10(a)","§11.10(f)"],"fda_cyber":["524B-4","CRA-1","PU-1","ST-1","ST-2","ST-3","ST-4","TM-1"],"hitrust_csf":["09.b","10.b","10.d"],"iso_27799":["14.2","14.3"],"lloyds_ms":["BP2.1","MS8.4","MS8.11"],"naic_ds":["4-config"],"nhs_dspt":[],"pra_ss1_23":["P3.3","P4.2","P4.3"],"solvency_ii":["EIOPA-ICT-4.11"],"owasp_masvs_v2":["MASVS-CODE-3","MASVS-CODE-4","MASVS-PLATFORM-2","MASVS-RESILIENCE-1"],"csa_ccm_v4":["AIS-02","AIS-03","AIS-04","AIS-05","AIS-07","CCC-02","TVM-05"],"csa_aicm":["AIS-02","AIS-03","AIS-04","AIS-05","AIS-07","AIS-09","AIS-10","AIS-13","AIS-15","CCC-02","MDS-03","MDS-08","TVM-05","TVM-12"],"ccss_v9":["1.02.7"],"mica":[],"basel_sco60":["SCO60.14","SCO60.21","SCO60.51","SCO60.52"],"bssc":["GSP-08","GSP-15","NOS-02","TIS-02","TIS-04"],"sec_custody_digital":[],"dpdpa":["Rules.13(3)"]},"attack_techniques":[{"id":"T1078","name":"Valid Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Security testing validates that default and test accounts are removed before production deployment, preventing adversaries from exploiting well-known credentials left in released software."},{"id":"T1495","name":"Firmware Corruption","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Security testing of firmware update mechanisms identifies vulnerabilities in image verification and signing that adversaries exploit to corrupt device firmware for permanent damage."},{"id":"T1505","name":"Server Software Component","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Security testing of server software identifies extensibility vulnerabilities in web servers, mail servers, and databases that adversaries exploit to install persistent server-side components."},{"id":"T1528","name":"Steal Application Access Token","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Security testing of OAuth implementations and token handling identifies token generation weaknesses and scope validation flaws that adversaries exploit to steal application access tokens."},{"id":"T1542","name":"Pre-OS Boot","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Security testing of firmware update mechanisms and boot processes identifies vulnerabilities that adversaries could exploit for pre-OS boot persistence through bootkit or UEFI implant installation."},{"id":"T1552","name":"Unsecured Credentials","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Security testing identifies hardcoded credentials, insecure credential storage, and secrets exposure in source code and configuration files before adversaries can discover them."},{"id":"T1553","name":"Subvert Trust Controls","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Security testing of code signing and certificate validation implementations identifies trust control weaknesses that adversaries could exploit to execute unsigned malicious code."},{"id":"T1601","name":"Modify System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Security testing of firmware update mechanisms identifies vulnerabilities in image validation and integrity checking that adversaries exploit to modify network device system images."},{"id":"T1612","name":"Build Image on Host","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Security testing of container build processes identifies vulnerabilities in image construction that adversaries exploit to build malicious container images on production hosts."},{"id":"T1647","name":"Plist File Modification","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Security testing identifies plist file handling vulnerabilities on macOS that adversaries exploit to modify application and system configurations for persistence and defense evasion."},{"id":"T1078.001","name":"Default Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Security testing validates that all default accounts are disabled or removed and that default passwords are changed, eliminating the known credential set adversaries commonly target."},{"id":"T1078.003","name":"Local Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Security testing identifies local accounts with weak passwords, excessive privileges, or missing lockout policies that adversaries exploit for persistent access on individual systems."},{"id":"T1078.004","name":"Cloud Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Security testing of cloud IAM configurations identifies overly-permissive cloud accounts, missing MFA, and excessive role assignments that adversaries exploit for cloud-based access."},{"id":"T1134.005","name":"SID-History Injection","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Security testing of Active Directory configurations identifies SID-History vulnerabilities and excessive trust relationships that adversaries exploit to inject security identifiers for privilege escalation."},{"id":"T1195.001","name":"Compromise Software Dependencies and Development Tools","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Dependency scanning and SBOM analysis in the development pipeline detects compromised or vulnerable third-party libraries before adversaries can exploit supply chain compromises."},{"id":"T1195.003","name":"Compromise Hardware Supply Chain","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Hardware security testing validates component authenticity and firmware integrity, detecting supply chain modifications to hardware before deployment in production environments."},{"id":"T1213.003","name":"Code Repositories","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Security testing of code repository access controls identifies overly-permissive permissions, missing branch protections, and exposed secrets that adversaries exploit to access source code."},{"id":"T1505.001","name":"SQL Stored Procedures","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Security testing identifies SQL injection vulnerabilities that adversaries exploit to install malicious stored procedures for persistent database-level code execution and data exfiltration."},{"id":"T1505.002","name":"Transport Agent","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Security testing of Exchange transport agent interfaces identifies extensibility vulnerabilities that adversaries exploit to install malicious mail transport agents for email interception."},{"id":"T1505.004","name":"IIS Components","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Security testing of IIS module loading identifies web server extensibility vulnerabilities that adversaries exploit to install malicious ISAPI filters and managed modules."},{"id":"T1542.001","name":"System Firmware","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Security testing of UEFI firmware update mechanisms identifies validation bypasses that adversaries exploit to install persistent system firmware implants."},{"id":"T1542.003","name":"Bootkit","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Security testing of boot integrity mechanisms identifies Secure Boot bypasses and MBR protection weaknesses that adversaries exploit for bootkit installation."},{"id":"T1542.004","name":"ROMMONkit","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Security testing of network device ROM Monitor access controls identifies authentication weaknesses that adversaries exploit to install ROMMONkit firmware implants."},{"id":"T1542.005","name":"TFTP Boot","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Security testing of network boot configurations identifies TFTP authentication and integrity weaknesses that adversaries exploit to redirect boot processes to compromised images."},{"id":"T1552.001","name":"Credentials In Files","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Security testing scans source code and configuration files for hardcoded credentials, API keys, and plaintext passwords that adversaries discover through file system enumeration."},{"id":"T1552.002","name":"Credentials in Registry","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Security testing identifies applications storing credentials in registry keys without proper encryption, eliminating the accessible credential stores that adversaries target."},{"id":"T1552.004","name":"Private Keys","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Security testing identifies exposed private keys, insecure key storage, and missing key rotation that adversaries exploit to authenticate using stolen cryptographic material."},{"id":"T1552.006","name":"Group Policy Preferences","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Security testing identifies Group Policy Preferences containing cpassword values and validates that credential storage policies prevent plaintext password exposure in SYSVOL."},{"id":"T1553.006","name":"Code Signing Policy Modification","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Security testing of code signing policy enforcement identifies configuration weaknesses that adversaries exploit to modify signing requirements and execute unsigned binaries."},{"id":"T1558.004","name":"AS-REP Roasting","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Security testing identifies Kerberos accounts configured without pre-authentication requirements, which adversaries target for offline AS-REP roasting credential attacks."},{"id":"T1559.003","name":"XPC Services","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Security testing of macOS XPC service implementations identifies inter-process communication vulnerabilities that adversaries exploit for privilege escalation through insecure XPC connections."},{"id":"T1574.002","name":"DLL Side-Loading","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Security testing identifies DLL side-loading vulnerabilities in applications that load unsigned libraries from writable locations, which adversaries exploit to inject malicious code."},{"id":"T1601.001","name":"Patch System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Security testing of network device firmware update mechanisms identifies authentication and validation weaknesses that adversaries exploit to apply malicious patches to system images."},{"id":"T1601.002","name":"Downgrade System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Security testing validates firmware version enforcement controls to prevent adversaries from downgrading network devices to older, vulnerable system images."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: nist_csf_2 ID.IM-01, ID.IM-02, ID.IM-03, ID.RA-09 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base. 2026-10-03: baselines --- to -MH, from NIST SP 800-53B Release 5.2.0.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-011","SP-012","SP-027","SP-028","SP-030","SP-035","SP-038","SP-041","SP-045","SP-047","SP-048","SP-049","SP-050","SP-051","SP-052","SP-053","SP-054"]}}