PlumbTrackLive demoGRC Risk System

← control library

Developer Security and Privacy Architecture and Design SA-17

System and Services Acquisition · High baseline ✗ Not implemented

Status — program-wide

What references this control

No risks name this control in their Framework field yet.

No policies reference it yet.


Link a risk or policy to this control

Attaching adds SA-17 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.

Source: NIST SP 800-53 Rev.5, System and Services Acquisition family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.

Control guide — plain-English, per NIST SP 800-53

SA-17 (Developer Security and Privacy Architecture and Design) asks the builder to produce a real design document — a security and privacy architecture — that lines up with the organization's overall architecture, describes exactly which security functions are needed and where each control lives, and explains how those controls work together to protect the system. It is a High-baseline control, aimed at systems built from the ground up. In short: design the security on paper first, and show the pieces fit.

What good looks like

Framework mapping

How to move it toward Implemented