NIST SP 800-53 r4 Security Control SA-17 (3): Formal Correspondence, v4
Profile of requirements corresponding to NIST Special Publication 800-53, r4, Security Control SA-17 (3): Formal Correspondence.
Identifier | https://artifacts.trustmarkinitiative.org/lib/tips/nist-sp-800-53-r4-security-control-sa-17-_3__-formal-correspondence/4/ | ||||
Publication Date | 2021-04-26 | ||||
Issuing Organization |
Trustmark Initiative (https://trustmarkinitiative.org/)
View Contact
|
||||
Keywords | 800-53, Formal Correspondence, NIST, Security, Services Acquisition, System | ||||
Legal Notice | This document and the information contained herein is provided on an "AS IS" basis, and the Georgia Tech Research Institute disclaims all warranties, express or implied, including but not limited to any warranty that the use of the information herein will not infringe any rights or any implied warranties or merchantability or fitness for a particular purpose. In addition, the Georgia Tech Research Institute disclaims legal liability for any loss incurred as a result of the use or reliance on the document or the information contained herein. |
Loading...
Trust Expression:
TD_ref1 and TD_ref2 and TD_ref3 and TD_ref4 and TD_ref5
References (5)
TD Developer Security Architecture And Design | Formal Correspondence | Top-Level Specification Covers Interfaces, v1.0 | |
---|---|
Description | Defines conformance and assessment criteria for verifying that an organization requires the developer of the information system, system component, or information system service to show via informal demonstration, that the formal top-level specification completely covers the interfaces to security-relevant hardware, software, and firmware. |
ID | TD_ref1 |
Provider Reference |
TD Developer Security Architecture And Design | Formal Correspondence | Top-Level Specification, v1.0 | |
---|---|
Description | Defines conformance and assessment criteria for verifying that an organization requires the developer of the information system, system component, or information system service to produce, as an integral part of the development process, a formal top-level specification that specifies the interfaces to security-relevant hardware, software, and firmware in terms of exceptions, error messages, and effects. |
ID | TD_ref2 |
Provider Reference |
TD Developer Security Architecture And Design | Formal Correspondence | Top-Level Specification Consistent With Policy Model, v1.0 | |
---|---|
Description | Defines conformance and assessment criteria for verifying that an organization requires the developer of the information system, system component, or information system service to show via proof to the extent feasible with additional informal demonstration as necessary, that the formal top-level specification is consistent with the formal policy model. |
ID | TD_ref3 |
Provider Reference |
TD Developer Security Architecture And Design | Formal Correspondence | Description of Additional Security-Relevant Items, v1.0 | |
---|---|
Description | Defines conformance and assessment criteria for verifying that an organization requires the developer of the information system, system component, or information system service to describe the security-relevant hardware, software, and firmware mechanisms not addressed in the formal top-level specification but strictly internal to the security-relevant hardware, software, and firmware. |
ID | TD_ref4 |
Provider Reference |
TD Developer Security Architecture And Design | Formal Correspondence | Top-Level Specification Is Accurate, v1.0 | |
---|---|
Description | Defines conformance and assessment criteria for verifying that an organization requires the developer of the information system, system component, or information system service to show that the formal top-level specification is an accurate description of the implemented security-relevant hardware, software, and firmware. |
ID | TD_ref5 |
Provider Reference |
Sources (1)
SP800-53R4 | NIST Special Publication 800-53 Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations, National Institute of Standards and Technology, April 2013 (Includes updates as of 01-15-2014). Available at http://dx.doi.org/10.6028/NIST.SP.800-53r4. |