NIST SP 800-53 Rev. 5
SA-17(4)
System and Services Acquisition
enhancement

Informal Correspondence

Parent: SA-17

Description

Require the developer of the system, system component, or system service to: a. Produce, as an integral part of the development process, an informal descriptive top-level specification that specifies the interfaces to security-relevant hardware, software, and firmware in terms of exceptions, error messages, and effects; b. Show via [organization-defined parameter] that the descriptive top-level specification is consistent with the formal policy model; c. Show via informal demonstration, that the descriptive top-level specification completely covers the interfaces to security-relevant hardware, software, and firmware; d. Show that the descriptive top-level specification is an accurate description of the interfaces to security-relevant hardware, software, and firmware; and e. Describe the security-relevant hardware, software, and firmware mechanisms not addressed in the descriptive top-level specification but strictly internal to the security-relevant hardware, software, and firmware.

Mapped SPARTA techniques

No techniques mapped to this control.

Cite as SafeMode Space, nist-80053-rev5 SA-17(4).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.