Publications
Withdrawn on May 31, 2019.
The System Development Life Cycle (SDLC)
Documentation
Date Published: April 2009
Author(s)
Shirley Radack (NIST)
This bulletin summarizes the information that was disseminated by the National Institute of Standards and Technology (NIST) in Special Publication (SP) 800-64, Revision 2, Security Considerations in the System Development Life Cycle. This publication was developed by Richard Kissel, Kevin Stine, and Matthew Scholl of NIST, with the assistance of Hart Rossman, Jim Fahlsing and Jessica Gulick, of Science Applications International Corporation (SAIC), and issued in October 2008. The bulletin discusses the topics presented in SP 800-64, and briefly describes the five phases of the system development life cycle (SDLC) process, which is the overall process of developing, implementing, and retiring information systems from initiation, analysis, design, implementation, and maintenance to disposal. The benefits of integrating security into each phase of the system development life cycle are presented. Information is provided about other NIST standards and guidelines that organizations can draw upon in carrying out their SDLC activities.
This bulletin summarizes the information that was disseminated by the National Institute of Standards and Technology (NIST) in Special Publication (SP) 800-64, Revision 2, Security Considerations in the System Development Life Cycle. This publication was developed by Richard Kissel, Kevin Stine, and...
See full abstract
This bulletin summarizes the information that was disseminated by the National Institute of Standards and Technology (NIST) in Special Publication (SP) 800-64, Revision 2, Security Considerations in the System Development Life Cycle. This publication was developed by Richard Kissel, Kevin Stine, and Matthew Scholl of NIST, with the assistance of Hart Rossman, Jim Fahlsing and Jessica Gulick, of Science Applications International Corporation (SAIC), and issued in October 2008. The bulletin discusses the topics presented in SP 800-64, and briefly describes the five phases of the system development life cycle (SDLC) process, which is the overall process of developing, implementing, and retiring information systems from initiation, analysis, design, implementation, and maintenance to disposal. The benefits of integrating security into each phase of the system development life cycle are presented. Information is provided about other NIST standards and guidelines that organizations can draw upon in carrying out their SDLC activities.
Hide full abstract
Keywords
Federal Information Processing Standards; information security; risk management; security categorization; security controls; security planning; system development; system life cycle
Control Families
None selected