SA-17(2)

  • Requirement

    Require the developer of the system, system component, or system service to:
    (a) Define security-relevant hardware, software, and firmware; and
    (b) Provide a rationale that the definition for security-relevant hardware, software, and firmware is complete.

  • Discussion

    The security-relevant hardware, software, and firmware represent the portion of the system, component, or service that is trusted to perform correctly to maintain required security properties.

More Info

  • Title

    Developer Security and Privacy Architecture and Design | Security-relevant Components
  • Family

    System and Services Acquisition
  • NIST 800-53B Baseline(s)

    • Related NIST 800-53 ID

      AC-25;SA-5

    NIST 800-53A Assessment Guidance

    CMMC Training

    Our CMMC Overview Course simplifies CMMC. Enroll so you can make informed decisions!