SA-11 Developer Testing and Evaluation
Description
Information security should be considered throughout the development, testing and evaluation of a university information resource.
Applicability
- The information resource owner, or designee, is responsible for ensuring that the measures described in this Control are implemented. This Control applies to software and applications that are developed by university employees, or for applications where the custodian has full access to the application source code (e.g. open-source software projects).
Implementation
-
1The information resource owner, or designee shall require the developer of the information resource to document and implement a plan for ongoing security and privacy testing and evaluation.
-
2Security and privacy testing shall be performed periodically based on risk management decisions.
-
3The Security and privacy testing and evaluation plan shall include the following elements: