The International Foundation for Information Technology (IF4IT)
  • Home
  • Best Practices & More
  • Articles
  • About Us
  • Contact Us
  • Catalog
  • Search
Systems Development Lifecycle (SDLC) Best Practices
Each SDLC phase should identify its applicable Policies (mandatory enterprise intent), Standards (required criteria and controls), Procedures (governed execution steps), Best Practices (recommended approaches), and Guidelines (adaptable advice), along with the owner, current vers

How SDLC Phases Should Link to Policies, Standards, Procedures, Best Practices, and Guidelines - Systems Development Lifecycle (SDLC) Best Practices

How SDLC Phases Should Link to Policies, Standards, Procedures, Best Practices, and Guidelines

(Chapter 23 of Systems Development Lifecycle (SDLC) Best Practices)

Executive Summary: Chapter Overview

IF4IT

💡 The Bottom Line

Each SDLC phase should identify its applicable Policies (mandatory enterprise intent), Standards (required criteria and controls), Procedures (governed execution steps), Best Practices (recommended approaches), and Guidelines (adaptable advice), along with the owner, current version, and evidence expectations for each. Mappings should also account for Asset and Solution type, sourcing model, data classification, and regulatory exposure, since Custom-Built and Acquired work may satisfy the same obligation through different mechanisms and evidence.

📝 Core Concepts

ConceptDefinition & Strategic Role
Guidance MappingA governed relationship between lifecycle context and applicable enterprise resources.
Authority ClassificationThe status of a resource as mandatory, recommended, contextual, optional, or illustrative.
Applicability MetadataControlled information identifying when guidance applies.

🤖 Quick Q&A

Question: Should phase pages copy every Standard?

Answer: No. They should explain phase context and link to the authoritative source.

Question: Is a Best Practice mandatory?

Answer: Not inherently. Its authority and intended use should be stated explicitly.

⬇ Read More Below ⬇

Authored and Published By: The International Foundation for Information Technology (IF4IT), LLC

Previous Chapter <<Table of Contents>> Next Chapter

This chapter defines how phase guidance should connect practitioners to authoritative and supporting enterprise resources.

Best Practice: Apply Authority and Purpose

Policy establishes mandatory enterprise intent and accountability. Standards define required criteria, controls, conventions, or minimum practices. Procedures define governed execution steps. Best Practices recommend effective approaches. Guidelines provide adaptable advice. Patterns, templates, examples, and reference architectures are supporting resources.

**Benefits:**Distinguishing Policy’s mandatory intent from a Guideline’s adaptable advice means practitioners know exactly how much latitude they have with a given piece of guidance, rather than treating every published document as carrying the same binding weight.

Best Practice: Apply Contextual Phase Mapping

Each phase should identify applicable guidance, why it applies, its authority classification, owner, current version, evidence expectations, tailoring or exception path, and the Activities, roles, Artifacts, and Gates it supports.

Benefits: Requiring each phase to identify why a given piece of guidance applies, not just that it applies, gives practitioners the reasoning behind a requirement, which makes it far easier to recognize when a genuinely different context might call for a different approach.

Best Practice: Apply Applicability and Sourcing

Mappings should account for Asset and Solution type, sourcing model, data classification, exposure, regulation, geography, safety, criticality, supplier involvement, AI, Environment, and risk. Custom-Built and Acquired work may satisfy the same obligation through different mechanisms and evidence.

Benefits: Accounting for sourcing model and data classification when mapping guidance to a phase means a Custom-Built Solution and an Acquired one can each satisfy the same underlying obligation through mechanisms actually suited to how they’re built or acquired, rather than forcing identical evidence expectations onto fundamentally different delivery contexts.

Best Practice: Apply Technical Debt and Authoritative Systems

Phase guidance should link Technical Debt responsibilities to the Technical Debt Management Best Practices, Technical Debt Inventory and Attributes, and enterprise Registry. It should also link directly to applicable inventories, workflows, and systems of record rather than duplicating them.

Benefits: Linking phase guidance directly to the Technical Debt Inventory and other systems of record, rather than duplicating their content, means practitioners always see the current authoritative version instead of a potentially stale copy embedded in phase documentation.

Best Practice: Advance Maturity Deliberately for How SDLC Phases Should Link to Policies, Standards, Procedures, Best Practices, and Guidelines

At Crawl maturity, maintain a manually curated list of applicable guidance for each phase, reviewed periodically by the accountable owner. At Walk maturity, publish a structured phase-guidance mapping with authority classifications and review dates, kept current through a defined maintenance process. At Run maturity, maintain the mapping through integrated metadata so guidance updates automatically propagate to affected phases, and use governed AI to surface the most relevant, current guidance contextually.

Benefits: Starting with a manually curated list at Crawl maturity ensures the mapping is grounded in actual practitioner need before investing in more sophisticated tooling. Publishing a structured, reviewed mapping at Walk maturity keeps guidance current as policies evolve. Pursuing automated propagation and AI-assisted retrieval at Run maturity accelerates access to current guidance once the underlying mapping is already reliable.

How SDLC Phases Should Link to Policies, Standards, Procedures, Best Practices, and Guidelines — How SDLC Phases Link to…
Figure: How SDLC Phases Link to Policies, Standards, Procedures, Best Practices, and Artifacts.

Common Antipatterns

Enterprises should avoid treating a Guideline’s adaptable advice as having the same binding force as a Policy. Policy establishes mandatory intent while Guidelines provide adaptable advice; treating a Guideline as equally binding removes legitimate flexibility, while treating a Policy as merely advisory can let a genuinely mandatory control get skipped.

AntipatternWhy it fails
Treating a Guideline’s adaptable advice as having the same binding force as a PolicyPolicy establishes mandatory intent while Guidelines provide adaptable advice; treating a Guideline as equally binding removes legitimate flexibility, and treating a Policy as advisory can let a mandatory control be skipped.

Connections to Related IF4IT Practices and Inventories

Use the IF4IT Enterprise Model together with Enterprise Capability Models and the Capabilities Inventory and Attributes to anchor this chapter’s decisions in enterprise structure, capability ownership, and measurable business outcomes. Use Technology Portfolio Management (TPM) Best Practices, the Software Technologies Inventory and Attributes, and IT Operating Environments Best Practices to connect the decisions and responsibilities addressed in this chapter to governed technology choices, platform lifecycle, and environment controls.

Enterprise Inventory Management Best Practices require each Release to read authoritative lifecycle records and update affected inventories, identifiers, relationships, ownership, status, evidence, configuration, and retirement information as governed outputs.

Previous Chapter <<Table of Contents>> Next Chapter

How to cite this page

When referencing this page in academic work, internal standards, or external publications, include the page title, IF4IT as author and publisher (The International Foundation for Information Technology (IF4IT), LLC), the URL, and your access date.

Example (informal web citation):

The International Foundation for Information Technology (IF4IT), LLC. How SDLC Phases Should Link to Policies, Standards, Procedures, Best Practices, and Guidelines | Systems Development Lifecycle (SDLC) Best Practices. https://if4it.org/best-practices/systems-development-lifecycle-sdlc/how-sdlc-phases-should-link-to-policies-standards-procedures-best-practices-and-guidelines/ (accessed 2026-09-11).

See About Us for content governance and site-wide citation guidance.

Copyright for The International Foundation for Information Technology (IF4IT), LLC: 2008 - Present

Legal Disclaimers
Share:
Contact Us → Subscribe →
© The International Foundation for Information Technology (IF4IT) 2008 - Present
Legal Disclaimers