SA-11 Developer Testing and Evaluation
Last Review: 10/1/22
Statement
WTAMU requires that developers of information system services, both internal and external, perform proper configuration management during all post-design stages of the SDLC.
Applicability
This Control applies to all West Texas A&M information resources. The intended audience for this Control includes all information resource developers, owners, and custodians of information resources.
Implementation
The developers of information systems, or components shall do the following:
- Develop and implement a plan for ongoing security and privacy assessments
- Perform proper security testing and evaluation based on risk decisions
- Produce evidence of the execution assessment plan and the results of testing and evaluation
- Implement a verifiable flaw remediation process
- Correct flaws identified during testing and evaluation