SA-11 Developer testing and evaluation
Requires the developer, at all stages after design, to plan and perform ongoing security and privacy control assessment, to carry out defined testing types at a defined frequency, depth and coverage, to produce evidence
4
artefacts
1
held by a system
1
at each review
moderate
to go live
Document repository
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Flaw remediation records showing identified flaws corrected and verified · Document repository
periodic reviewEvidence produced at each review
- Test execution evidence and results supplied by the developer · Document repository
governing documentDocuments that govern the control
- Developer assessment and test plan covering the required testing types · Policy repository / GRC workspace
- Contract clauses requiring the testing depth, coverage and frequency · Vendor register / contract repository
First move
Start with the 1 of 4 artefacts that already live in a system (Document repository); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Testing evidence claimed but never provided to the organization for review
- Depth and coverage undefined, so a single scan satisfies the requirement on paper
- Flaws found in testing closed without verification that the fix works
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetSA-10 Developer configuration management · SA-15 Development process, standards, and tools