Cyber Resilience

NIST 800-53 r5 · Controls catalogue · Family SA

SA-3System Development Life Cycle

Acquire, develop, and manage the system using {{ insert: param, sa-03_odp }} that incorporates information security and privacy considerations; Define and document information security and privacy roles and responsibilities throughout the system development life cycle; Identify individuals having information security and privacy roles and responsibilities; and Integrate the organizational information security and privacy risk management process into system development life cycle activities.

Last updated: 22 August 2026 07:11 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: partial · 1 mapping(s) from 1 framework(s): OWASP-Web 1 (partial)

See the full cumulative-coverage rollup →

Implementations targeting this control (2)

ATT&CK techniques this control mitigates (6)

Weaknesses this control addresses (9)AI-assisted

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-862Missing Authorization10,200+Requiring security roles and risk processes throughout the SDLC ensures that authorization checks are identified as requirements and implemented for every sensitive operation.
CWE-284Improper Access Control6,900+Defining security roles/responsibilities and integrating risk management into the SDLC directly reduces improper access control by ensuring access decisions are designed and reviewed throughout development.
CWE-287Improper Authentication5,200+Requiring explicit security roles and risk integration in the SDLC forces authentication mechanisms to be planned, documented, and validated instead of omitted or weakly implemented.
CWE-798Use of Hard-coded Credentials2,000+Integrating risk management and security responsibilities into the SDLC makes use of hard-coded credentials visible during design and code reviews, reducing their introduction.
CWE-732Incorrect Permission Assignment for Critical Resource1,900+Documented roles, responsibilities, and continuous risk management in the SDLC ensure that default and runtime permissions for critical resources are deliberately assigned and reviewed.
CWE-285Improper Authorization1,500+Incorporating security considerations and risk management into every SDLC phase ensures authorization logic is properly specified, implemented, and tested rather than added ad hoc.
CWE-311Missing Encryption of Sensitive Data500+Privacy and security considerations mandated across the SDLC make identification and protection of sensitive data (including encryption decisions) a required activity rather than an afterthought.
CWE-1104Use of Unmaintained Third Party Components26Acquisition and development under a security-aware SDLC includes evaluation of third-party components for maintenance status and known weaknesses before integration.
CWE-657Violation of Secure Design Principles20The control explicitly requires adoption of an SDLC that incorporates security considerations, directly preventing violation of established secure design principles.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2024-36912 6.99.60.0096partial
CVE-2025-15480 6.89.10.0031partial
CVE-2024-36913 6.69.30.0065partial
CVE-2025-14551 6.08.10.0028partial
CVE-2026-664325.87.50.0040partial
CVE-2026-526965.77.50.0024partial
CVE-2025-32257 4.65.30.0080partial
CVE-2025-26482 3.94.90.0029partial
CVE-2026-269483.94.90.0029partial
CVE-2024-52289 7.59.80.0106partial
CVE-2024-523247.49.80.0069partial
CVE-2024-44852 7.49.80.0059partial
CVE-2025-14233 7.49.80.0078partial
CVE-2025-55050 7.29.80.0034partial
CVE-2025-12176 7.29.80.0032partial
CVE-2026-52993 7.29.80.0037partial
CVE-2017-20204 7.09.30.0084partial
CVE-2024-6607 6.68.80.0056partial
CVE-2025-25215 6.68.80.0206partial
CVE-2023-36346.68.80.0050partial
CVE-2026-749476.48.80.0024partial
CVE-2024-2955 6.17.80.0140partial
CVE-2025-48431 6.17.50.0108partial
CVE-2025-417566.08.10.0033partial
CVE-2024-52564 5.97.50.0058partial

Other controls in family SA

SA-1 SA-10 SA-11 SA-12 SA-13 SA-14 SA-15 SA-16 SA-17 SA-18 SA-19 SA-2 SA-20 SA-21 SA-22 SA-23 SA-24 SA-4 SA-5 SA-6 SA-7 SA-8 SA-9