← Controls / SA

SA-03 System Development Life Cycle

System and Services Acquisition

Low Moderate High Privacy

Description

a. Acquire, develop, and manage the system using [Assignment: organization-defined system development life cycle] that incorporates information security and privacy considerations; b. Define and document information security and privacy roles and responsibilities throughout the system development life cycle; c. Identify individuals having information security and privacy roles and responsibilities; and d. Integrate the organizational information security and privacy risk management process into system development life cycle activities.

Supplemental Guidance

A system development life cycle process provides the foundation for the successful development, implementation, and operation of organizational systems. The integration of security and privacy considerations early in the system development life cycle is a foundational principle of systems security engineering and privacy engineering. To apply the required controls within the system development life cycle requires a basic understanding of information security and privacy, threats, vulnerabilities, adverse impacts, and risk to critical mission and business functions. The security engineering principles in SA-08 help individuals properly design, code, and test systems and system components. Organizations include qualified personnel (e.g., senior agency information security officers, senior agency officials for privacy, security and privacy architects, and security and privacy engineers) in system development life cycle processes to ensure that established security and privacy requirements are incorporated into organizational systems. Role-based security and privacy training programs can ensure that individuals with key security and privacy roles and responsibilities have the experience, skills, and expertise to conduct assigned system development life cycle activities. The effective integration of security and privacy requirements into enterprise architecture also helps to ensure that important security and privacy considerations are addressed throughout the system life cycle and that those considerations are directly related to organizational mission and business processes. This process also facilitates the integration of the information security and privacy architectures into the enterprise architecture, consistent with the risk management strategy of the organization. Because the system development life cycle involves multiple organizations, (e.g., external suppliers, developers, integrators, service providers), acquisition and supply chain risk management functions and controls play significant roles in the effective management of the system during the life cycle.

Changes from Rev 4

Control text adds privacy Discussion is expanded to include benefits of effective integration of security and privacy requirements into enterprise architecture

Enhancements (3)

What NIST adds to this control. Select one to read its statement.

SA-03(01) Manage Preproduction Environment

Protect system preproduction environments commensurate with risk throughout the system development life cycle for the system, system component, or system service.

SA-03(02) Use of Live or Operational Data

a. Approve, document, and control the use of live data in preproduction environments for the system, system component, or system service; and b. Protect preproduction environments for the system, system component, or system service at the same impact or classification level as any live data in use within the preproduction environments.

SA-03(03) Technology Refresh

Plan for and implement a technology refresh schedule for the system throughout the system development life cycle.

Compliance Mappings

ISO 27001:2022

7.1A.5.2A.5.8A.8.25A.8.31

ISO 27002:2022

5.88.25

COBIT 2019

BAI01BAI03BAI11EDM04

CIS Controls v8

CIS 16CIS 16.1

NIST CSF 2.0

GV.SC-09ID.AM-08PR.PS-06

SOC 2 TSC

CC5.2CC8.1CC8.1-POF1

PCI DSS v4.0.1

6.16.2

CSA CCM v4

AIS-04AIS-06IVS-07

CSA AICM v1

AIS-04AIS-06AIS-11AIS-15I&S-07MDS-02MDS-04MDS-10MDS-11

ISO 42001:2023

A.6.1.2A.6.1.3

NIS2 Directive

Art. 21(2)(e)

MAS TRM

56

ANSSI

Hygiene.34Hygiene.36SecNumCloud.15.1

FINMA Circular 2023/1

IV.A(28)IV.A(36)IV.A(37)

OSFI B-13

B-13.2.1B-13.2.2

EU GDPR

Art.25(1)Art.28(1)

EU DORA

Art.7(1)Art.8(5)

BIO2

5.88.25

RBI CSF

Annex1.6ITGRCA.12

FISC Security Guidelines

FISC.O10FISC.T1FISC.T6

HKMA TM-E-1

TME1.3.1TME1.3.2

MLPS 2.0

8.1.9.48.1.9.5

DNB Good Practice

DNB.19.3

EU CRA

CRA.I.1

SAMA CSF

1.43.2

NCA ECC

1-6

UAE IA

T10

CBB TM

TM-7

Qatar NIA

SD

CBUAE

CR-6

CBE CSF

CTO-4

SA JS2

JS2-SA

BoG CISD

CISD-IXCISD-SDLC

BoM CTRM

1.33.73.11

IOSCO Cyber Resilience

PROT-6

BCBS 239

Principle 2Principle 6

FFIEC IS

I.CII.C.2II.C.17

NYDFS 500

500.8

EBA ICT Guidelines

3.5(a)3.5(b)3.6.13.6.2

SEBI CSCRF

PR.ASPR.IP

BOT Cyber Resilience

Ch2.5Ch6.2

IEEE 1686-2022

5.10

PCI PTS v6

H

FIPS 140-3

FIPS 140-3 §7.11

Common Criteria

CC Part 3 — SAR

ISAE 3402

Clause 4

Solvency II

EIOPA-ICT-4.11

Lloyd's Minimum Standards

BP2.1MS1.1

NAIC Insurance Data Security

4-config

PRA SS1/23

P3.1P5.5

FCA SYSC 13

SYSC 13.7.1SYSC 13.8.4

HITRUST CSF v11

09.b10.a10.d

FDA 21 CFR Part 11

§11.10(a)

FDA Cybersecurity Guidance

SPDF-1

ISO 27799

14.114.2

MiCA

Art.62(5)

Basel SCO60

SCO60.52

ISO 17799 (legacy)

None.

COBIT 4.1 (legacy)

PO8.3AI2.7