{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Secure Development (SDLC) & Application Security","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-SDLC-11","description":"Identify components critical to security or mission and, where commercial items cannot meet requirements, use customized or specialized development, such as reimplementation, custom variants, or context-specific augmentation, to reduce supply-chain and assurance risk. Document the rationale and assurance evidence for each specialized component.","details":{"control_category":"administrative","control_type":"preventive","domain":"Secure Development (SDLC) & Application Security","guidance":[],"members":[{"control_id":"SA-20","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SA-23","coverage":"full","framework":"nist-800-53","relationship":"superset_of"}],"statement":"Identify components critical to security or mission and, where commercial items cannot meet requirements, use customized or specialized development, such as reimplementation, custom variants, or context-specific augmentation, to reduce supply-chain and assurance risk. Document the rationale and assurance evidence for each specialized component.","title":"Apply specialized development to critical components","unified_id":"UC-SDLC-11"},"id":"uc:UC-SDLC-11","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-SDLC-11","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"UC-SDLC-11 — Apply specialized development to critical components","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:043720cf9cd31dbe678a12b73d62fc32982139c9e940b50b5d2535bf6e29ad50","properties":{"rationale":"Reimplementing or building custom variants of critical components reduces reliance on backdoored or concentrated third-party models and libraries.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-11-153d74aa.json","sourceId":"uc:UC-SDLC-11","targetDetailPath":"/data/v1/records/risk-ai-supply-chain-concentration-9f791f54.json","targetId":"risk:ai-supply-chain-concentration","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1fd339e8dc8375611aaa45979ec3654de7f911719bbb713a6f461eb79b05fda3","properties":{"rationale":"Custom-developing critical components avoids malicious code paths embedded in commercial/third-party software.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-11-153d74aa.json","sourceId":"uc:UC-SDLC-11","targetDetailPath":"/data/v1/records/risk-sdlc-malware-injection-compromise-ec5a8dc4.json","targetId":"risk:sdlc-malware-injection-compromise","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2869898568ce9caa544db398308e1c30f9cae6e9b3fce208eac2a2ab1aeabf92","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-sdlc-11-153d74aa.json","targetId":"uc:UC-SDLC-11","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:43a29b3197724b04905330a374a6e614eda2f53dbb6aa442440de7ab46ee7be2","properties":{"control_id":"SA-23","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-11-153d74aa.json","sourceId":"uc:UC-SDLC-11","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sa-23-145ec5c7.json","targetId":"ctrl:nist-800-53:SA-23","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:76fa21c8e34eebc4ed16fd823134d811433d1d66dabd8679327463fb74fcc068","properties":{},"sourceDetailPath":"/data/v1/records/wf-c63-6a1e26cb.json","sourceId":"wf:C63","targetDetailPath":"/data/v1/records/uc-uc-sdlc-11-153d74aa.json","targetId":"uc:UC-SDLC-11","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8009145d165772f7e5b69b77aa9ff141e005f411f7a72aae2af74b448271fe2a","properties":{"control_id":"SA-20","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-11-153d74aa.json","sourceId":"uc:UC-SDLC-11","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sa-20-8537fd4a.json","targetId":"ctrl:nist-800-53:SA-20","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:edf7c481fd614b92be79dfc69f09750b963d40c5080104996dad923baae16327","properties":{"rationale":"Custom/specialized reimplementation of critical components explicitly reduces supply-chain injection of tampered third-party parts.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-11-153d74aa.json","sourceId":"uc:UC-SDLC-11","targetDetailPath":"/data/v1/records/risk-tprm-supply-chain-injection-ad1f5937.json","targetId":"risk:tprm-supply-chain-injection","type":"mitigates"}],"schemaVersion":1}
