NIST SP 800-53 Rev. 5
SA-11(2)
System and Services Acquisition
enhancement

Threat Modeling and Vulnerability Analyses

Parent: SA-11

Description

Require the developer of the system, system component, or system service to perform threat modeling and vulnerability analyses during development and the subsequent testing and evaluation of the system, component, or service that: a. Uses the following contextual information: [organization-defined parameter]; b. Employs the following tools and methods: [organization-defined parameter]; c. Conducts the modeling and analyses at the following level of rigor: [organization-defined parameter] ; and d. Produces evidence that meets the following acceptance criteria: [organization-defined parameter].

Mapped SPARTA techniques

83 techniques

Cite as SafeMode Space, nist-80053-rev5 SA-11(2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.