SA-4(2) - Acquisition Process | Design and Implementation Information for Controls

Require the developer of the system, system component, or system service to provide design and implementation information for the controls that includes: [Selection (one or more): security-relevant external system interfaces; high-level design; low-level design; source code or hardware schematics; [Assignment: organization-defined design and implementation information] ] at [Assignment: organization-defined level of detail].


ID: SA-4(2)
Enhancement of : SA-4

Space Segment Guidance

When deeper insight is needed, ask for design/implementation information sufficient to assess risk while protecting proprietary data. Examples include high-level architecture, ICDs, attack-surface summaries, fault-management interactions, and data-flow diagrams showing cryptographic boundaries and trust anchors. Define handling/marking requirements and redaction expectations so multinational teams can share what’s necessary without oversharing.