Implementation of SDLC Roles and Responsibilities, v1.1
Specifies requirements in accordance with NIST Secure Software Development Framework (SSDF), version 1.1, Practice PO.2: Implementation of SDLC Roles and Responsibilities. Requires an organization to ensure that everyone inside and outside of the organization involved in the SDLC is prepared to perform their SDLC-related roles and responsibilities throughout the SDLC.
Assessment Steps (3)
1
SDLC Roles and Responsibilities (SDLCRolesandResponsibilities)
Does the organization create new roles and alter responsibilities for existing roles as needed to encompass all parts of the SDLC, and periodically review and maintain the defined roles and responsibilities, updating them as needed?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
2
SDLC Role-Based Training (SDLCRole-BasedTraining)
Does the organization provide role-based training for all personnel with responsibilities that contribute to secure development, periodically review personnel proficiency and role-based training, and update the training as needed?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
3
Executive Commitment to Secure Software Development (ExecutiveCommitmenttoSecureSoftwareDevelopment)
Does the organization obtain upper management or authorizing official commitment to secure development, and convey that commitment to all with development-related roles and responsibilities?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (3)
SDLC Roles and Responsibilities
The organization must create new roles and alter responsibilities for existing roles as needed to encompass all parts of the SDLC, and periodically review and maintain the defined roles and responsibilities, updating them as needed.
Citation
SSDF
Task PO.2.1
|
SDLC Role-Based Training
The organization must provide role-based training for all personnel with responsibilities that contribute to secure development. It must also periodically review personnel proficiency and role-based training, and update the training as needed.
Citation
SSDF
Task PO.2.2
|
Executive Commitment to Secure Software Development
The organization must obtain upper management or authorizing official commitment to secure development, and convey that commitment to all with development-related roles and responsibilities.
Citation
SSDF
Task PO.2.3
|