NIST SP 800-53 Rev. 5
SA-11
System and Services Acquisition

Developer Testing and Evaluation

Description

Require the developer of the system, system component, or system service, at all post-design stages of the system development life cycle, to: a. Develop and implement a plan for ongoing security and privacy control assessments; b. Perform [organization-defined parameter] testing/evaluation [organization-defined parameter] at [organization-defined parameter]; c. Produce evidence of the execution of the assessment plan and the results of the testing and evaluation; d. Implement a verifiable flaw remediation process; and e. Correct flaws identified during testing and evaluation.

Mapped SPARTA techniques

104 techniques

Cite as SafeMode Space, nist-80053-rev5 SA-11.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.