Cyber Resilience

NIST 800-53 r5 · Controls catalogue · Family SA

SA-11Developer Testing and Evaluation

Require the developer of the system, system component, or system service, at all post-design stages of the system development life cycle, to: Develop and implement a plan for ongoing security and privacy control assessments; Perform {{ insert: param, sa-11_odp.01 }} testing/evaluation {{ insert: param, sa-11_odp.02 }} at {{ insert: param, sa-11_odp.03 }}; Produce evidence of the execution of the assessment plan and the results of the testing and evaluation; Implement a verifiable flaw remediation process; and Correct flaws identified during testing and evaluation.

Last updated: 22 August 2026 14:14 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (34)

Weaknesses this control addresses (10)AI-assisted

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-119Improper Restriction of Operations within the Bounds of a Memory Buffer14,500+Ongoing control assessments and code testing (static/dynamic analysis, fuzzing) surface memory buffer restriction failures, which are then remediated before release.
CWE-20Improper Input Validation14,000+Security testing and evaluation at multiple SDLC stages directly detects missing or flawed input validation, with the required remediation process ensuring fixes are applied.
CWE-284Improper Access Control6,900+Explicit security control assessments verify proper access control enforcement, detecting weaknesses that the flaw remediation process then eliminates.
CWE-74Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')5,200+Developer assessments and testing (including injection-focused techniques) identify improper neutralization of special elements, and the verifiable flaw remediation corrects them pre-deployment.
CWE-287Improper Authentication5,200+Authentication mechanism testing and evaluation during development identifies bypass or weakness conditions, with mandatory correction prior to system delivery.
CWE-400Uncontrolled Resource Consumption3,800+Resource consumption and denial-of-service testing performed under the assessment plan detects uncontrolled allocation paths that are subsequently fixed.
CWE-502Deserialization of Untrusted Data3,600+Evaluation of untrusted data handling (deserialization testing) reveals unsafe processing, which the required remediation process addresses.
CWE-754Improper Check for Unusual or Exceptional Conditions700+Security testing routinely checks for unusual or exceptional inputs/conditions, identifying missing validation steps that flaw remediation then resolves.
CWE-693Protection Mechanism Failure700+Assessments of security controls directly validate whether protection mechanisms function as intended, exposing failures for correction.
CWE-703Improper Check or Handling of Exceptional Conditions100+Testing and evaluation exercises error paths and exceptional conditions, surfacing improper handling that is then remediated through the defined process.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2024-21650 10.010.00.9348good
CVE-2024-1212 KEV 10.010.00.9539good
CVE-2024-3094 10.010.00.8597good
CVE-2024-2389 10.010.00.9304good
CVE-2024-3400 KEV 10.010.01.0000good
CVE-2024-32651 10.010.00.8360good
CVE-2024-29895 10.010.00.9429good
CVE-2024-25600 10.010.00.8823good
CVE-2024-45519 KEV 10.010.00.9991good
CVE-2024-51378 KEV 10.010.00.9473good
CVE-2024-50603 KEV 10.010.00.9855good
CVE-2025-24085 KEV 10.010.00.1765good
CVE-2025-24201 KEV 10.010.00.0412good
CVE-2025-32432 KEV 10.010.00.9984good
CVE-2025-47916 10.010.00.8373good
CVE-2025-43300 KEV 10.010.00.2039good
CVE-2025-10035 KEV 10.010.00.9958good
CVE-2025-5952810.010.00.9123good
CVE-2025-55182 KEV 10.010.00.9962good
CVE-2025-37164 KEV 10.010.00.9019good
CVE-2025-20393 KEV 10.010.00.2988good
CVE-2026-20131 KEV 10.010.00.3123good
CVE-2026-34910 KEV 10.010.00.8696good
CVE-2026-10520 KEV 10.010.00.9990good
CVE-2026-16812 KEV10.010.00.0088good

Other controls in family SA

SA-1 SA-10 SA-12 SA-13 SA-14 SA-15 SA-16 SA-17 SA-18 SA-19 SA-2 SA-20 SA-21 SA-22 SA-23 SA-24 SA-3 SA-4 SA-5 SA-6 SA-7 SA-8 SA-9