SA-3 System development life cycle
Requires the system to be acquired, developed and managed using an organization-defined system development life cycle that incorporates security and privacy considerations, with security and privacy roles defined and doc
4
artefacts
1
held by a system
1
at each review
moderate
to go live
Document repository
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Records showing the life cycle was actually followed for this system · Document repository
periodic reviewEvidence produced at each review
- Evidence risk management activities are integrated into life cycle gates · Document repository
governing documentDocuments that govern the control
- Documented system development life cycle showing security and privacy activities at each stage · Policy repository / GRC workspace
- Defined security and privacy roles across the life cycle and the named individuals holding them · Policy repository / GRC workspace
First move
Start with the 1 of 4 artefacts that already live in a system (Document repository); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Life cycle documented centrally while delivery teams follow their own process
- Security roles defined but unassigned, so nobody performs the activity
- Risk management runs parallel to delivery instead of gating it
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet