EvidenceSheet

SA-15(3) Development Process, Standards, and Tools | Criticality Analysis. Require the developer of the system, system component, or system service to perform a criticality analysis: (a) At the following decision points in the system development

Development Process, Standards, and Tools | Criticality Analysis. Require the developer of the system, system component, or system service to perform a criticality analysis: (a) At the following decision points in the sy.

5
artefacts
1
held by a system
3
at each review
hard
to go live
Document repository
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • The developer's criticality analysis output identifying critical components and functions · Document repository

periodic reviewEvidence produced at each review

  • Evidence the analysis was performed at the defined decision points in the development life cycle · Document repository
  • Evidence the analysis was performed at the defined level of detail or decomposition · Document repository
  • Organisational review of the developer's analysis and the actions taken on its findings · Document repository

governing documentDocuments that govern the control

  • Contract or solicitation clause requiring the developer to perform criticality analysis · Vendor register / contract repository

First move

Mostly documents and reviews. Pull the 1 system-held artefact from your Document repository on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

SA-15 Development Process, Standards, and Tools. a. Require the developer of the system, system component, or system service to follow a documented development process that: 1. Explicitly addresses security and privacy requirements; 2. Identifies the · SA-22 Unsupported System Components. a. Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer; or b. Provide the following options for alternative sources for continued support