Risk Management Guide for IT: SDLC
NIST 800-30, risk management guide for IT discusses how risk management framework matches to the system development life cycle (SDLC) , risk assessment methodology, risk mitigation, and good practice of ongoing risk assessment.
A system and its information must be protected from cradle to grave. That is why risk management applies to the entire system development life cycle. The level of risk to the system and its data depends on the criticality or importance of the system to the business and/or mission it supports.
The system development life cycle consists of: Initiation, Development/Acquisition, Implementation, Maintenance/Operations, and Disposal.
How Risk Management Framework matches to the System Development Life Cycle
|
SDLC |
Phase |
Support |
|
Phase |
The need expressed scope of documented |
Identified support system security security (strategy) |
|
Phase Acquisition |
The IT purchased, developed, constructed |
The risks phase can the system architecture during development |
|
Phase |
The system should be tested, |
The risk supports system its modeled environment. regarding be made operation |
|
Phase Maintenance |
The system functions. being basis hardware changes to processes, procedures |
Risk performed reauthorization reaccreditation) major IT system production new system |
|
Phase |
This phase disposition hardware, Activities archiving, destroying sanitizing software |
Risk are components disposed ensure software of, that appropriately system in a manner |