unified
UC-SDLC-11 — Apply specialized development to critical components
Identify components critical to security or mission and, where commercial items cannot meet requirements, use customized or specialized development, such as reimplementation, custom variants, or context-specific augmentation, to reduce supply-chain and assurance risk. Document the rationale and assurance evidence for each specialized component.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Secure Development (SDLC) & Application Security
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-SDLC-11
- title
- Apply specialized development to critical components
- statement
- Identify components critical to security or mission and, where commercial items cannot meet requirements, use customized or specialized development, such as reimplementation, custom variants, or context-specific augmentation, to reduce supply-chain and assurance risk. Document the rationale and assurance evidence for each specialized component.
- domain
- Secure Development (SDLC) & Application Security
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- SA-20
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- SA-23
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-SDLC-11 — Apply specialized development to critical components mitigates AI supply-chain compromise and provider concentration
- strength
- primary
- rationale
- Reimplementing or building custom variants of critical components reduces reliance on backdoored or concentrated third-party models and libraries.
- UC-SDLC-11 — Apply specialized development to critical components mitigates Malware delivery, insertion and compromise of systems
- strength
- related
- rationale
- Custom-developing critical components avoids malicious code paths embedded in commercial/third-party software.
- Security Control Assessment & POA&M Remediation tests UC-SDLC-11 — Apply specialized development to critical components
- UC-SDLC-11 — Apply specialized development to critical components maps_to SA-23 — Specialization
- framework
- nist-800-53
- control_id
- SA-23
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Outsourced & Critical-Component Development Oversight operates UC-SDLC-11 — Apply specialized development to critical components
- UC-SDLC-11 — Apply specialized development to critical components maps_to SA-20 — Customized Development of Critical Components
- framework
- nist-800-53
- control_id
- SA-20
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-SDLC-11 — Apply specialized development to critical components mitigates Malicious supply-chain injection of tampered hardware/software
- strength
- primary
- rationale
- Custom/specialized reimplementation of critical components explicitly reduces supply-chain injection of tampered third-party parts.