SA-3—System Development Life Cycle
>Control Description
a
Acquire, develop, and manage the system using ⚙organization-defined system development life cycle that incorporates information security and privacy considerations;
b
Define and document information security and privacy roles and responsibilities throughout the system development life cycle;
c
Identify individuals having information security and privacy roles and responsibilities; and
d
Integrate the organizational information security and privacy risk management process into system development life cycle activities.
>Related Controls
Ask AI
Configure your API key to use AI features.