← Controls / SA

SA-11 Developer Testing and Evaluation

System and Services Acquisition

Moderate High Privacy

Description

Require the developer of the system, system component, or system service, at all post-design stages of the system development life cycle, to: a. Develop and implement a plan for ongoing security and privacy control assessments; b. Perform [Selection (one or more): unit; integration; system; regression] testing/evaluation [Assignment: organization-defined frequency] at [Assignment: organization-defined depth and coverage]; c. Produce evidence of the execution of the assessment plan and the results of the testing and evaluation; d. Implement a verifiable flaw remediation process; and e. Correct flaws identified during testing and evaluation.

Supplemental Guidance

Developmental testing and evaluation confirms that the required controls are implemented correctly, operating as intended, enforcing the desired security and privacy policies, and meeting established security and privacy requirements. Security properties of systems and the privacy of individuals may be affected by the interconnection of system components or changes to those components. The interconnections or changes—including upgrading or replacing applications, operating systems, and firmware—may adversely affect previously implemented controls. Ongoing assessment during development allows for additional types of testing and evaluation that developers can conduct to reduce or eliminate potential flaws. Testing custom software applications may require approaches such as manual code review, security architecture review, and penetration testing, as well as and static analysis, dynamic analysis, binary analysis, or a hybrid of the three analysis approaches. Developers can use the analysis approaches, along with security instrumentation and fuzzing, in a variety of tools and in source code reviews. The security and privacy assessment plans include the specific activities that developers plan to carry out, including the types of analyses, testing, evaluation, and reviews of software and firmware components; the degree of rigor to be applied; the frequency of the ongoing testing and evaluation; and the types of artifacts produced during those processes. The depth of testing and evaluation refers to the rigor and level of detail associated with the assessment process. The coverage of testing and evaluation refers to the scope (i.e., number and type) of the artifacts included in the assessment process. Contracts specify the acceptance criteria for security and privacy assessment plans, flaw remediation processes, and the evidence that the plans and processes have been diligently applied. Methods for reviewing and protecting assessment plans, evidence, and documentation are commensurate with the security category or classification level of the system. Contracts may specify protection requirements for documentation.

Changes from Rev 4

Title changed from 'Developer Security Testing and Evaluation' Control text adds 'ongoing' and 'privacy' New parameter to specify frequency Discussion expanded to include privacy considerations

Enhancements (9)

What NIST adds to this control. Select one to read its statement.

SA-11(01) Static Code Analysis

Require the developer of the system, system component, or system service to employ static code analysis tools to identify common flaws and document the results of the analysis.

SA-11(02) Threat Modeling and Vulnerability Analyses

Require the developer of the system, system component, or system service to perform threat modeling and vulnerability analyses during development and the subsequent testing and evaluation of the system, component, or service that: a. Uses the following contextual information: [Assignment: organization-defined information concerning impact, environment of operations, known or assumed threats, and acceptable risk levels]; b. Employs the following tools and methods: [Assignment: organization-defined tools and methods]; c. Conducts the modeling and analyses at the following level of rigor: [Assignment: organization-defined breadth and depth of modeling and analyses]; and d. Produces evidence that meets the following acceptance criteria: [Assignment: organization-defined acceptance criteria].

SA-11(03) Independent Verification of Assessment Plans and Evidence

a. Require an independent agent satisfying [Assignment: organization-defined independence criteria] to verify the correct implementation of the developer security and privacy assessment plans and the evidence produced during testing and evaluation; and b. Verify that the independent agent is provided with sufficient information to complete the verification process or granted the authority to obtain such information.

SA-11(04) Manual Code Reviews

Require the developer of the system, system component, or system service to perform a manual code review of [Assignment: organization-defined specific code] using the following processes, procedures, and/or techniques: [Assignment: organization-defined processes, procedures, and/or techniques].

SA-11(05) Penetration Testing

Require the developer of the system, system component, or system service to perform penetration testing: a. At the following level of rigor: [Assignment: organization-defined breadth and depth of testing]; and b. Under the following constraints: [Assignment: organization-defined constraints].

SA-11(06) Attack Surface Reviews

Require the developer of the system, system component, or system service to perform attack surface reviews.

SA-11(07) Verify Scope of Testing and Evaluation

Require the developer of the system, system component, or system service to verify that the scope of testing and evaluation provides complete coverage of the required controls at the following level of rigor: [Assignment: organization-defined breadth and depth of testing and evaluation].

SA-11(08) Dynamic Code Analysis

Require the developer of the system, system component, or system service to employ dynamic code analysis tools to identify common flaws and document the results of the analysis.

SA-11(09) Interactive Application Security Testing

Require the developer of the system, system component, or system service to employ interactive application security testing tools to identify flaws and document the results.

MITRE ATT&CK Techniques (34)

ATT&CK v16.1

Techniques mitigated by this control, mapped via CTID.

Initial Access 6 Execution 1 Persistence 14 Privilege Escalation 6 Defense Evasion 18 Credential Access 7 Collection 1 Impact 1
Show all 34 techniques grouped by tactic

Compliance Mappings

ISO 27001:2022

A.8.25A.8.28A.8.29A.8.30A.8.31A.8.33

ISO 27002:2022

8.258.268.288.298.308.318.33

COBIT 2019

APO11BAI03BAI07

CIS Controls v8

CIS 16CIS 16.2CIS 16.3CIS 16.8CIS 16.12CIS 16.13

NIST CSF 2.0

ID.IM-01ID.IM-02ID.IM-03ID.RA-09PR.PS-06

SOC 2 TSC

CC4.1-POF1

PCI DSS v4.0.1

6.26.2.36.4

CSA CCM v4

AIS-02AIS-03AIS-04AIS-05AIS-07CCC-02TVM-05

CSA AICM v1

AIS-02AIS-03AIS-04AIS-05AIS-07AIS-09AIS-10AIS-13AIS-15CCC-02MDS-03MDS-08TVM-05TVM-12

ISO 42001:2023

A.6.2.4

NIS2 Directive

Art. 21(2)(e)

MAS TRM

6

BSI IT-Grundschutz

APP.3.1OPS.1.1.6

ANSSI

Hygiene.31Hygiene.33SecNumCloud.15.5

FINMA Circular 2023/1

IV.A(36)IV.A(37)IV.D(75)IV.D(76)

OSFI B-13

B-13.3.2B-13.3.5

EU GDPR

Art.25(1)Art.32(1)(d)

EU DORA

Art.9(4)(e)Art.25(1)Art.25(2)

BIO2

8.258.268.288.298.308.318.33

RBI CSF

Annex1.6Annex1.18

FISC Security Guidelines

FISC.O10FISC.T6

LGPD + BCB 4893

BCB.Art.10

HKMA TM-E-1

TME1.3.2TME1.3.3

MLPS 2.0

8.1.9.48.1.9.5

DNB Good Practice

DNB.10.3DNB.10.4DNB.22.1

EU CRA

CRA.I.1CRA.I.2aCRA.II.2CRA.II.3

SWIFT CSCF

SWIFT.2.10

SAMA CSF

3.2

NCA ECC

1-62-32-102-112-14

UAE IA

T7T10

CBB TM

TM-7

Qatar NIA

SD

CBUAE

CR-6

CBE CSF

CTO-4

SA JS2

JS2-7.7JS2-SA

CBN CSF

Part5.2

BoG CISD

CISD-IXCISD-SDLC

BoM CTRM

3.11

IOSCO Cyber Resilience

PROT-6SA-3TEST-1TEST-3

BCBS 239

Principle 3Principle 7

CPMI-IOSCO PFMI

CG.TEPFMI.P17

FFIEC IS

II.C.15(b)II.C.17IV.AIV.A.2

NYDFS 500

500.5500.8

ECB CROE

CROE.2.3.4CROE.2.6.1

EBA ICT Guidelines

3.4.63.6.2

SEBI CSCRF

PR.ASPR.IP

BOT Cyber Resilience

Ch2.5

TSA Pipeline SD

SD-2 Sec G

IEEE 1686-2022

5.10

PCI PTS v6

F

FIPS 140-3

FIPS 140-3 §7.5FIPS 140-3 §7.11FIPS 140-3 §7.12

Common Criteria

CC Part 2 — FPTCC Part 3 — SARCEM

ISAE 3402

Clause 4

Solvency II

EIOPA-ICT-4.11

Lloyd's Minimum Standards

BP2.1MS8.4MS8.11

NAIC Insurance Data Security

4-config

PRA SS1/23

P3.3P4.2P4.3

FCA SYSC 13

SYSC 13.7.1SYSC 13.7.4

HITRUST CSF v11

09.b10.b10.d

FDA 21 CFR Part 11

§11.10(a)§11.10(f)

FDA Cybersecurity Guidance

524B-4CRA-1PU-1ST-1ST-2ST-3ST-4TM-1

ISO 27799

14.214.3

OWASP MASVS v2.1

MASVS-CODE-3MASVS-CODE-4MASVS-PLATFORM-2MASVS-RESILIENCE-1

CCSS v9.0

1.02.7

Basel SCO60

SCO60.14SCO60.21SCO60.51SCO60.52

BSSC Standards

GSP-08GSP-15NOS-02TIS-02TIS-04

India DPDPA

Rules.13(3)