NIST 800-53 r5 · Controls catalogue · Family SA
SA-17Developer Security and Privacy Architecture and Design
Require the developer of the system, system component, or system service to produce a design specification and security and privacy architecture that: Is consistent with the organization’s security and privacy architecture that is an integral part the organization’s enterprise architecture; Accurately and completely describes the required security and privacy functionality, and the allocation of controls among physical and logical components; and Expresses how individual security and privacy functions, mechanisms, and services work together to provide required security and privacy capabilities and a unified approach to protection.
Last updated: 22 August 2026 14:14 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: partial · 2 mapping(s) from 1 framework(s): OWASP-Web 2 (partial)
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (7)
- T1078 Valid Accounts Stealth, Persistence, Privilege Escalation, Initial Access
- T1078.001 Default Accounts Stealth, Persistence, Privilege Escalation, Initial Access
- T1078.003 Local Accounts Stealth, Persistence, Privilege Escalation, Initial Access
- T1078.004 Cloud Accounts Stealth, Persistence, Privilege Escalation, Initial Access
- T1134.005 SID-History Injection Stealth, Privilege Escalation
- T1482 Domain Trust Discovery Discovery
- T1574.001 DLL Stealth, Execution
Weaknesses this control addresses (7)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-284 | Improper Access Control | 6,900+ | Requires explicit allocation of controls to physical and logical components, directly preventing architectural gaps in access enforcement. |
CWE-306 | Missing Authentication for Critical Function | 3,300+ | Demands complete description of required security functionality, making omission of authentication for critical functions far less likely. |
CWE-732 | Incorrect Permission Assignment for Critical Resource | 1,900+ | Mandates accurate specification of control allocation, making incorrect default or assigned permissions on critical resources less probable at design time. |
CWE-693 | Protection Mechanism Failure | 700+ | Requires demonstrating integration of mechanisms into a coherent protection strategy, reducing failures from poorly composed or conflicting controls. |
CWE-1220 | Insufficient Granularity of Access Control | 100+ | Requires the architecture to describe granularity and placement of controls, preventing insufficiently fine-grained access decisions. |
CWE-653 | Improper Isolation or Compartmentalization | 73 | Requires the architecture to show how functions work together as a unified protection approach, reducing improper isolation or compartmentalization. |
CWE-657 | Violation of Secure Design Principles | 20 | Enforces production of a design consistent with secure architecture principles and enterprise goals, directly addressing violation of secure design principles. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2026-32841 UPD | 6.2 | 8.1 | 0.0060 | partial |
CVE-2024-57176 UPD | 5.8 | 7.6 | 0.0051 | partial |
CVE-2024-47827 UPD | 4.5 | 5.7 | 0.0036 | partial |
CVE-2024-58311 UPD | 7.3 | 9.8 | 0.0041 | partial |
CVE-2025-8850 UPD | 6.5 | 8.8 | 0.0041 | partial |
CVE-2026-8806 | 5.5 | 8.7 | 0.0064 | partial |
CVE-2026-65934 | 5.5 | 7.1 | 0.0010 | partial |
CVE-2025-6211 UPD | 5.1 | 6.5 | 0.0031 | partial |
CVE-2025-52953 UPD | 5.0 | 6.5 | 0.0029 | partial |
CVE-2026-42752 | 5.0 | 6.5 | 0.0022 | partial |
CVE-2024-47762 UPD | 4.5 | 5.8 | 0.0037 | partial |
CVE-2025-27094 UPD | 4.4 | 5.4 | 0.0035 | partial |
CVE-2023-43052 UPD | 4.4 | 5.3 | 0.0035 | good |
CVE-2025-3044 UPD | 4.4 | 5.3 | 0.0028 | partial |
CVE-2026-41136 | 4.4 | 5.3 | 0.0028 | partial |
CVE-2024-7246 UPD | 4.3 | 5.3 | 0.0022 | partial |
CVE-2025-48508 UPD | 4.3 | 6.0 | 0.0015 | partial |
CVE-2025-13940 UPD | 4.1 | 5.5 | 0.0012 | partial |
CVE-2024-31068 UPD | 3.9 | 5.3 | 0.0024 | partial |
CVE-2024-56202 UPD | 3.9 | 4.3 | 0.0084 | partial |
CVE-2026-3344 UPD | 3.9 | 4.9 | 0.0028 | partial |
CVE-2024-24968 UPD | 3.8 | 5.3 | 0.0018 | partial |
CVE-2025-27401 UPD | 3.8 | 4.6 | 0.0032 | partial |
CVE-2024-21853 UPD | 3.7 | 4.7 | 0.0021 | partial |
CVE-2025-40555 UPD | 3.6 | 4.7 | 0.0021 | partial |