FedRAMP Controls / SA

SA-11 Developer Testing and Evaluation

Family SA
Baselines moderate
Mapped KSIs 1

Control statement

Require the developer of the system, system component, or system service, at all post-design stages of the system development life cycle, to:
    a. Develop and implement a plan for ongoing security and privacy control assessments;
    b. Perform {{ insert: param, sa-11_odp.01 }} testing/evaluation {{ insert: param, sa-11_odp.02 }} at {{ insert: param, sa-11_odp.03 }};
    c. Produce evidence of the execution of the assessment plan and the results of the testing and evaluation;
    d. Implement a verifiable flaw remediation process; and
    e. Correct flaws identified during testing and evaluation.

Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is preserved in the catalog database.

Covered by these Key Security Indicators

KSITitleCategory
KSI-TPR-03Supply Chain Risk Management
_Persistently_ identify, review, and mitigate potential supply chain risks.
Third-Party Information Resources