SA-17(2): Security-relevant Components

CSF v1.1 References:

Baselines:

(Not part of any baseline)

Previous Version:

Control Statement

Require the developer of the system, system component, or system service to:

  1. Define security-relevant hardware, software, and firmware; and
  2. Provide a rationale that the definition for security-relevant hardware, software, and firmware is complete.

Supplemental Guidance

The security-relevant hardware, software, and firmware represent the portion of the system, component, or service that is trusted to perform correctly to maintain required security properties.