# SA-17 — Developer Security and Privacy Architecture and Design

- **Control ID:** SA-17
- **Family:** [SA](/md/families/SA.md)
- **Baselines:** high
- **Enhancement of:** No content available.

## Description

Require the developer of the system, system component, or system service to produce a design specification and security and privacy architecture that: Is consistent with the organization’s security and privacy architecture that is an integral part the organization’s enterprise architecture; Accurately and completely describes the required security and privacy functionality, and the allocation of controls among physical and logical components; and Expresses how individual security and privacy functions, mechanisms, and services work together to provide required security and privacy capabilities and a unified approach to protection.

## Discussion

Developer security and privacy architecture and design are directed at external developers, although they could also be applied to internal (in-house) development. In contrast, \[PL-8\](\#pl-8) is directed at internal developers to ensure that organizations develop a security and privacy architecture that is integrated with the enterprise architecture. The distinction between SA-17 and \[PL-8\](\#pl-8) is especially important when organizations outsource the development of systems, system components, or system services and when there is a requirement to demonstrate consistency with the enterprise architecture and security and privacy architecture of the organization. \[ISO 15408-2\](\#87087451-2af5-43d4-88c1-d66ad850f614), \[ISO 15408-3\](\#4452efc0-e79e-47b8-aa30-b54f3ef61c2f) , and \[SP 800-160-1\](\#e3cc0520-a366-4fc9-abc2-5272db7e3564) provide information on security architecture and design, including formal policy models, security-relevant components, formal and informal correspondence, conceptually simple design, and structuring for least privilege and testing.

## Implementation guidance

No content available.

## CSF 2.0 subcategories

- [ID.RA-09](/md/csf/ID.RA-09.md) — The authenticity and integrity of hardware and software are assessed prior to acquisition and use
- [PR.PS-06](/md/csf/PR.PS-06.md) — PR.PS-06

## Related controls

- [PL-2](/md/controls/PL-2.md)
- [PL-8](/md/controls/PL-8.md)
- [PM-7](/md/controls/PM-7.md)
- [SA-3](/md/controls/SA-3.md)
- [SA-4](/md/controls/SA-4.md)
- [SA-8](/md/controls/SA-8.md)
- [SC-7](/md/controls/SC-7.md)

---

Derived from official NIST publications (NIST SP 800-53 Rev 5 and NIST CSF 2.0). nistcontrols.com is not affiliated with NIST.
