# SA-03 System Development Life Cycle

NIST SP 800-53 control. Family: SA System and Services Acquisition. Function: preventative. Baselines: low, moderate, high, privacy. Mapping licence: CC BY-SA 4.0.

Statement: a. Acquire, develop, and manage the system using [Assignment: organization-defined system development life cycle] that incorporates information security and privacy considerations; b. Define and document information security and privacy roles and responsibilities throughout the system development life cycle; c. Identify individuals having information security and privacy roles and responsibilities; and d. Integrate the organizational information security and privacy risk management process into system development life cycle activities.
Guidance: A system development life cycle process provides the foundation for the successful development, implementation, and operation of organizational systems. The integration of security and privacy considerations early in the system development life cycle is a foundational principle of systems security engineering and privacy engineering. To apply the required controls within the system development life cycle requires a basic understanding of information security and privacy, threats, vulnerabilities, adverse impacts, and risk to critical mission and business functions. The security engineering principles in SA-08 help individuals properly design, code, and test systems and system components. Organizations include qualified personnel (e.g., senior agency information security officers, senior agency officials for privacy, security and privacy architects, and security and privacy engineers) in system development life cycle processes to ensure that established security and privacy requirements are incorporated into organizational systems. Role-based security and privacy training programs can ensure that individuals with key security and privacy roles and responsibilities have the experience, skills, and expertise to conduct assigned system development life cycle activities. The effective integration of security and privacy requirements into enterprise architecture also helps to ensure that important security and privacy considerations are addressed throughout the system life cycle and that those considerations are directly related to organizational mission and business processes. This process also facilitates the integration of the information security and privacy architectures into the enterprise architecture, consistent with the risk management strategy of the organization. Because the system development life cycle involves multiple organizations, (e.g., external suppliers, developers, integrators, service providers), acquisition and supply chain risk management functions and controls play significant roles in the effective management of the system during the life cycle.

## Enhancements (3)
- SA-03(01) Manage Preproduction Environment
- SA-03(02) Use of Live or Operational Data
- SA-03(03) Technology Refresh
Each enhancement's statement: /api/v1/controls/SA-03?fields=enhancements

## Patterns that use it (9)
- Important (5): SP-004 SOA Publication and Location Pattern; SP-008 Public Web Server Pattern; SP-024 iPhone Pattern; SP-045 AI Governance and Responsible AI; SP-049 AI in Security Operations (draft)
- Standard (4): SP-001 Client Module; SP-002 Server Module; SP-011 Cloud Computing Pattern; SP-025 Advanced Monitoring and Detection

## Clauses by framework (57 frameworks)
- iso_27001_2022: 7.1, A.5.2, A.5.8, A.8.25, A.8.31. OSA's own, not in NIST's crosswalk: 7.1
- iso_27002_2022: 5.8, 8.25
- cobit_2019: BAI01, BAI03, BAI11, EDM04
- pci_dss_v4: 6.1, 6.2
- nist_csf_2: GV.SC-09, ID.AM-08, PR.PS-06. OSA's own, not in NIST's crosswalk: GV.SC-09
- cis_controls_v8: CIS 16, CIS 16.1
- soc2_tsc: CC5.2, CC8.1, CC8.1-POF1
- iso_42001_2023: A.6.1.2, A.6.1.3
- nis2: Art. 21(2)(e)
- mas_trm: 5, 6
- anssi: Hygiene.34, Hygiene.36, SecNumCloud.15.1
- osfi_b13: B-13.2.1, B-13.2.2
- finma_circular: IV.A(28), IV.A(36), IV.A(37)
- gdpr: Art.25(1), Art.28(1)
- dora: Art.7(1), Art.8(5)
- bio2: 5.8, 8.25
- rbi_csf: Annex1.6, ITGRCA.12
- fisc: FISC.O10, FISC.T1, FISC.T6
- hkma_tme1: TME1.3.1, TME1.3.2
- mlps_2: 8.1.9.4, 8.1.9.5
- dnb_good_practice: DNB.19.3
- cra: CRA.I.1
- cbb_tm: TM-7
- cbuae: CR-6
- nca_ecc: 1-6
- qatar_nia: SD
- sama_csf: 1.4, 3.2
- uae_ia: T10
- bog_cisd: CISD-IX, CISD-SDLC
- bom_ctrm: 1.3, 3.7, 3.11
- cbe_csf: CTO-4
- sa_js2: JS2-SA
- bcbs_239: Principle 2, Principle 6
- bot_cyber: Ch2.5, Ch6.2
- eba_ict: 3.5(a), 3.5(b), 3.6.1, 3.6.2
- ffiec_is: I.C, II.C.2, II.C.17
- iosco_cyber: PROT-6
- nydfs_500: 500.8
- sebi_cscrf: PR.AS, PR.IP
- ieee_1686: 5.10
- pci_pts: H
- fips_140: FIPS 140-3 §7.11
- common_criteria: CC Part 3 — SAR
- isae_3402: Clause 4
- fca_sysc_13: SYSC 13.7.1, SYSC 13.8.4
- fda_21_cfr_11: §11.10(a)
- fda_cyber: SPDF-1
- hitrust_csf: 09.b, 10.a, 10.d
- iso_27799: 14.1, 14.2
- lloyds_ms: BP2.1, MS1.1
- naic_ds: 4-config
- pra_ss1_23: P3.1, P5.5
- solvency_ii: EIOPA-ICT-4.11
- csa_ccm_v4: AIS-04, AIS-06, IVS-07
- csa_aicm: AIS-04, AIS-06, AIS-11, AIS-15, I&S-07, MDS-02, MDS-04, MDS-10, MDS-11
- mica: Art.62(5)
- basel_sco60: SCO60.52
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/SA-03
- Clauses only: /api/v1/controls/SA-03?fields=mappings
- Page for people: /controls/sa-03/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
