NIST SP 800-53 r4 Security Control SA-15 (4): Threat Modeling / Vulnerability Analysis, v4
Profile of requirements corresponding to NIST Special Publication 800-53, r4, Security Control SA-15 (4): Threat Modeling / Vulnerability Analysis.

Trust Expression:
TD_ref1
References (1)
TD Development Process, Standards, And Tools | Threat Modeling / Vulnerability Analysis, v1.0 | |
---|---|
Description | Defines conformance and assessment criteria for verifying that an organization requires that developers perform threat modeling and a vulnerability analysis for the information system at organization-defined breadth/depth that: (a) Uses organization-defined information concerning impact, environment of operations, known or assumed threats, and acceptable risk levels; (b) Employs organization-defined tools and methods; and (c) Produces evidence that meets organization-defined acceptance criteria. . |
ID | TD_ref1 |
Provider Reference |
Sources (1)
SP800-53R4 | NIST Special Publication 800-53 Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations, National Institute of Standards and Technology, April 2013 (Includes updates as of 01-15-2014). Available at http://dx.doi.org/10.6028/NIST.SP.800-53r4. |