PlumbTrackLive demoGRC Risk System

← control library

System Development Life Cycle SA-3

System and Services Acquisition · Low baseline ✗ Not implemented

Status — program-wide

What references this control

No risks name this control in their Framework field yet.

No policies reference it yet.


Link a risk or policy to this control

Attaching adds SA-3 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.

Source: NIST SP 800-53 Rev.5, System and Services Acquisition family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.

Control guide — plain-English, per NIST SP 800-53

SA-3 (System Development Life Cycle) says that however you acquire, build, and run a system, you do it through a defined life cycle that bakes in security and privacy from day one — not bolted on at the end. It also asks you to name who holds the security and privacy roles at each stage and to fold risk management into that whole cycle. It is a Low-baseline control.

What good looks like

Framework mapping

How to move it toward Implemented