SA-4(3) - Acquisition Process | Development Methods, Techniques, and Practices

Require the developer of the system, system component, or system service to demonstrate the use of a system development life cycle process that includes: (a) [Assignment: organization-defined systems engineering methods]; (b) [Assignment: organization-defined Selection (one or more): systems security; privacy] engineering methods]; and (c) [Assignment: organization-defined software development methods; testing, evaluation, assessment, verification, and validation methods; and quality control processes].


ID: SA-4(3)
Enhancement of : SA-4

Space Segment Guidance

Set clear expectations for flaw remediation. Consider reporting/patch timelines, coordination of updates with pass schedules and no-change windows, availability of dual-bank/rollback, and distribution to partner stations. Define how advisories (CVE/KEV/vendor notices) are triaged against mission risk, what temporary compensating measures look like, and how status is communicated to operations with evidence from the twin/flatsat.