{"data":{"id":"SA-08","name":"Security and Privacy Engineering Principles","family":"SA","family_name":"System and Services Acquisition","withdrawn":false,"description":"Apply the following systems security and privacy engineering principles in the specification, design, development, implementation, and modification of the system and system components: [Assignment: organization-defined systems security and privacy engineering principles].","supplemental_guidance":"Systems security and privacy engineering principles are closely related to and implemented throughout the system development life cycle (see SA-03). Organizations can apply systems security and privacy engineering principles to new systems under development or to systems undergoing upgrades. For existing systems, organizations apply systems security and privacy engineering principles to system upgrades and modifications to the extent feasible, given the current state of hardware, software, and firmware components within those systems.\n\nThe application of systems security and privacy engineering principles helps organizations develop trustworthy, secure, and resilient systems and reduces the susceptibility to disruptions, hazards, threats, and the creation of privacy problems for individuals. Examples of system security and privacy engineering principles include: developing layered protections; establishing security and privacy policies, architecture, and controls as the foundation for design and development; incorporating security and privacy requirements into the system development life cycle; delineating physical and logical security boundaries; ensuring that developers are trained on how to build secure software; tailoring controls to meet organizational needs; and performing threat modeling to identify use cases, threat agents, attack vectors and patterns, design patterns, and compensating controls needed to mitigate risk.\n\nOrganizations that apply systems security and privacy engineering concepts and principles can facilitate the development of trustworthy, secure systems, system components, and system services; reduce risk to acceptable levels; and make informed risk management decisions. System security engineering principles can also be used to protect against certain supply chain risks, including incorporating tamper-resistant hardware into a design.","enhancements":[{"id":"SA-08(01)","name":"Clear Abstractions","statement":"Implement the security design principle of clear abstractions.","baselines":[]},{"id":"SA-08(02)","name":"Least Common Mechanism","statement":"Implement the security design principle of least common mechanism in [Assignment: organization-defined systems or system components].","baselines":[]},{"id":"SA-08(03)","name":"Modularity and Layering","statement":"Implement the security design principles of modularity and layering in [Assignment: organization-defined systems or system components].","baselines":[]},{"id":"SA-08(04)","name":"Partially Ordered Dependencies","statement":"Implement the security design principle of partially ordered dependencies in [Assignment: organization-defined systems or system components].","baselines":[]},{"id":"SA-08(05)","name":"Efficiently Mediated Access","statement":"Implement the security design principle of efficiently mediated access in [Assignment: organization-defined systems or system components].","baselines":[]},{"id":"SA-08(06)","name":"Minimized Sharing","statement":"Implement the security design principle of minimized sharing in [Assignment: organization-defined systems or system components].","baselines":[]},{"id":"SA-08(07)","name":"Reduced Complexity","statement":"Implement the security design principle of reduced complexity in [Assignment: organization-defined systems or system components].","baselines":[]},{"id":"SA-08(08)","name":"Secure Evolvability","statement":"Implement the security design principle of secure evolvability in [Assignment: organization-defined systems or system components].","baselines":[]},{"id":"SA-08(09)","name":"Trusted Components","statement":"Implement the security design principle of trusted components in [Assignment: organization-defined systems or system components].","baselines":[]},{"id":"SA-08(10)","name":"Hierarchical Trust","statement":"Implement the security design principle of hierarchical trust in [Assignment: organization-defined systems or system components].","baselines":[]},{"id":"SA-08(11)","name":"Inverse Modification Threshold","statement":"Implement the security design principle of inverse modification threshold in [Assignment: organization-defined systems or system components].","baselines":[]},{"id":"SA-08(12)","name":"Hierarchical Protection","statement":"Implement the security design principle of hierarchical protection in [Assignment: organization-defined systems or system components].","baselines":[]},{"id":"SA-08(13)","name":"Minimized Security Elements","statement":"Implement the security design principle of minimized security elements in [Assignment: organization-defined systems or system components].","baselines":[]},{"id":"SA-08(14)","name":"Least Privilege","statement":"Implement the security design principle of least privilege in [Assignment: organization-defined systems or system components].","baselines":[]},{"id":"SA-08(15)","name":"Predicate Permission","statement":"Implement the security design principle of predicate permission in [Assignment: organization-defined systems or system components].","baselines":[]},{"id":"SA-08(16)","name":"Self-reliant Trustworthiness","statement":"Implement the security design principle of self-reliant trustworthiness in [Assignment: organization-defined systems or system components].","baselines":[]},{"id":"SA-08(17)","name":"Secure Distributed Composition","statement":"Implement the security design principle of secure distributed composition in [Assignment: organization-defined systems or system components].","baselines":[]},{"id":"SA-08(18)","name":"Trusted Communications Channels","statement":"Implement the security design principle of trusted communications channels in [Assignment: organization-defined systems or system components].","baselines":[]},{"id":"SA-08(19)","name":"Continuous Protection","statement":"Implement the security design principle of continuous protection in [Assignment: organization-defined systems or system components].","baselines":[]},{"id":"SA-08(20)","name":"Secure Metadata Management","statement":"Implement the security design principle of secure metadata management in [Assignment: organization-defined systems or system components].","baselines":[]},{"id":"SA-08(21)","name":"Self-analysis","statement":"Implement the security design principle of self-analysis in [Assignment: organization-defined systems or system components].","baselines":[]},{"id":"SA-08(22)","name":"Accountability and Traceability","statement":"Implement the security design principle of accountability and traceability in [Assignment: organization-defined systems or system components].","baselines":[]},{"id":"SA-08(23)","name":"Secure Defaults","statement":"Implement the security design principle of secure defaults in [Assignment: organization-defined systems or system components].","baselines":[]},{"id":"SA-08(24)","name":"Secure Failure and Recovery","statement":"Implement the security design principle of secure failure and recovery in [Assignment: organization-defined systems or system components].","baselines":[]},{"id":"SA-08(25)","name":"Economic Security","statement":"Implement the security design principle of economic security in [Assignment: organization-defined systems or system components].","baselines":[]},{"id":"SA-08(26)","name":"Performance Security","statement":"Implement the security design principle of performance security in [Assignment: organization-defined systems or system components].","baselines":[]},{"id":"SA-08(27)","name":"Human Factored Security","statement":"Implement the security design principle of human factored security in [Assignment: organization-defined systems or system components].","baselines":[]},{"id":"SA-08(28)","name":"Acceptable Security","statement":"Implement the security design principle of acceptable security in [Assignment: organization-defined systems or system components].","baselines":[]},{"id":"SA-08(29)","name":"Repeatable and Documented Procedures","statement":"Implement the security design principle of repeatable and documented procedures in [Assignment: organization-defined systems or system components].","baselines":[]},{"id":"SA-08(30)","name":"Procedural Rigor","statement":"Implement the security design principle of procedural rigor in [Assignment: organization-defined systems or system components].","baselines":[]},{"id":"SA-08(31)","name":"Secure System Modification","statement":"Implement the security design principle of secure system modification in [Assignment: organization-defined systems or system components].","baselines":[]},{"id":"SA-08(32)","name":"Sufficient Documentation","statement":"Implement the security design principle of sufficient documentation in [Assignment: organization-defined systems or system components].","baselines":[]},{"id":"SA-08(33)","name":"Minimization","statement":"Implement the privacy principle of minimization using [Assignment: organization-defined processes].","baselines":["privacy"]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"SA-08","name":"Security and Privacy Engineering Principles","description":"Apply the following systems security and privacy engineering principles in the specification, design, development, implementation, and modification of the system and system components: [Assignment: organization-defined systems security and privacy engineering principles].","discussion":"Systems security and privacy engineering principles are closely related to and implemented throughout the system development life cycle (see SA-03). Organizations can apply systems security and privacy engineering principles to new systems under development or to systems undergoing upgrades. For existing systems, organizations apply systems security and privacy engineering principles to system upgrades and modifications to the extent feasible, given the current state of hardware, software, and firmware components within those systems.\n\nThe application of systems security and privacy engineering principles helps organizations develop trustworthy, secure, and resilient systems and reduces the susceptibility to disruptions, hazards, threats, and the creation of privacy problems for individuals. Examples of system security and privacy engineering principles include: developing layered protections; establishing security and privacy policies, architecture, and controls as the foundation for design and development; incorporating security and privacy requirements into the system development life cycle; delineating physical and logical security boundaries; ensuring that developers are trained on how to build secure software; tailoring controls to meet organizational needs; and performing threat modeling to identify use cases, threat agents, attack vectors and patterns, design patterns, and compensating controls needed to mitigate risk.\n\nOrganizations that apply systems security and privacy engineering concepts and principles can facilitate the development of trustworthy, secure systems, system components, and system services; reduce risk to acceptable levels; and make informed risk management decisions. System security engineering principles can also be used to protect against certain supply chain risks, including incorporating tamper-resistant hardware into a design.","related_controls":["PL-08","PM-07","RA-02","RA-03","RA-09","SA-03","SA-04","SA-15","SA-17","SA-20","SC-02","SC-03","SC-32","SC-39","SR-02","SR-03","SR-04","SR-05"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"Title changed from 'Security Engineering Principles' Control text adds privacy and system components New parameter requires specifying applicable systems security and privacy engineering principles Discussion expanded to explain benefits Incorporates withdrawn control SA-13"}},"compliance_mappings":{"iso_27001_2022":["A.8.25","A.8.26","A.8.27","A.8.28"],"iso_27002_2022":["5.8","8.25","8.26","8.27"],"cobit_2019":["APO03","APO04","BAI02","BAI03"],"pci_dss_v4":["6.2"],"nist_csf_2":["ID.AM-08","ID.IM-01","ID.IM-02","ID.IM-03","PR.DS-10","PR.IR-03","PR.PS-06"],"cis_controls_v8":["CIS 16","CIS 16.10","CIS 16.11","CIS 16.14"],"soc2_tsc":["CC2.2","CC3.2","CC5.1","CC5.2","CC6.1-POF2","CC6.1-POF7","CC6.7-POF1","CC7.1","CC7.1-POF1","CC8.1"],"finos_ccc":[],"iso_42001_2023":["A.6.1.2","A.6.1.3"],"iec_62443":[],"asd_e8":[],"nis2":["Art. 21(2)(e)"],"apra_cps_234":[],"mas_trm":["5","6"],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":["Hygiene.23","Hygiene.36","SecNumCloud.15.3"],"osfi_b13":["B-13.2.2","B-13.3.2"],"finma_circular":["IV.A(28)","IV.A(29)","IV.B.d(59)"],"gdpr":["Art.25(1)","Art.25(2)","Rec.78"],"dora":["Art.7(1)","Art.9(1)"],"bio2":["5.8","8.25","8.26","8.27"],"rbi_csf":["Annex1.6","ITGRCA.12"],"fisc":["FISC.O10","FISC.O13","FISC.T1","FISC.T6"],"lgpd_bcb":[],"hkma_tme1":["TME1.3.1","TME1.3.2","TME1.7.3"],"mlps_2":["8.1.9.4"],"dnb_good_practice":["DNB.2.1","DNB.3.2"],"cra":["CRA.I.1","CRA.I.2b","CRA.I.2g","CRA.I.2j"],"swift_cscf":[],"cbb_tm":["TM-7"],"cbuae":["CR-6"],"nca_ecc":["1-6","2-3","2-14","5-1"],"qatar_nia":["SD"],"sama_csf":["1.4","3.2"],"uae_ia":["T10"],"bog_cisd":["CISD-IX","CISD-SDLC"],"bom_ctrm":["3.1","3.11"],"cbe_csf":["CTO-4"],"cbn_csf":["Part4","Part5.1","Part5.2"],"sa_js2":["JS2-SA"],"bcbs_239":["Principle 2","Principle 6"],"bot_cyber":["Ch2.5","Ch6.2"],"cpmi_pfmi":["PFMI.P3","PFMI.P17"],"eba_ict":["3.4.4","3.6.1","3.6.2"],"ecb_croe":["CROE.2.3.4"],"ffiec_is":["II.C.2","II.C.3","II.C.17"],"iosco_cyber":["LE-3","PROT-6"],"nydfs_500":["500.8"],"sebi_cscrf":["PR.AS","PR.IP"],"cmmc_2":["SC"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":["SD-2 Sec F"],"ieee_1686":["5.10"],"ferc_cip":[],"doe_c2m2":["ARCHITECTURE"],"api_1164":["Sec 5"],"awia":[],"iaea_nss":["Sec 5.1"],"pci_pts":["F"],"fips_140":["FIPS 140-3 §7.2"],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":["CC Part 1 — PP","CC Part 1 — ST","CC Part 3 — SAR"],"isae_3402":[],"fca_sysc_13":["SYSC 13.7.1","SYSC 13.8.4"],"fda_21_cfr_11":["§11.10(a)"],"fda_cyber":["SPDF-1","SPDF-3","TM-2","TM-3"],"hitrust_csf":["09.b","10.a","10.d"],"iso_27799":["14.1","14.2"],"lloyds_ms":["BP2.1","MS1.1"],"naic_ds":["4-config"],"nhs_dspt":[],"pra_ss1_23":["P3.1"],"solvency_ii":["EIOPA-ICT-4.11"],"owasp_masvs_v2":["MASVS-CRYPTO-1","MASVS-CRYPTO-2","MASVS-PRIVACY-2","MASVS-RESILIENCE-2","MASVS-RESILIENCE-3","MASVS-RESILIENCE-4"],"csa_ccm_v4":["AIS-01","AIS-02","AIS-04","DSP-07"],"csa_aicm":["AIS-01","AIS-02","AIS-04","AIS-08","AIS-10","AIS-14","AIS-15","DSP-07","DSP-20","MDS-01","MDS-09","MDS-10"],"ccss_v9":[],"mica":["Art.62(5)","Art.68(1)","Art.68(5)","Art.69(1)","Art.70(1)","Art.72(1)"],"basel_sco60":["SCO60.2","SCO60.14","SCO60.21","SCO60.51","SCO60.52","SCO60.64","SCO60.65"],"bssc":["KMS-02","TIS-03"],"sec_custody_digital":["SEC-CD-03","SEC-CD-06","SEC-CD-08"],"dpdpa":["Act.6(1)","Act.8(4)","Rules.Sch2"]},"attack_techniques":[{"id":"T1005","name":"Data from Local System","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Defense-in-depth engineering ensures multiple independent data protection layers guard sensitive local data, so compromise of one control does not grant full access for adversary collection."},{"id":"T1025","name":"Data from Removable Media","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Applying least-functionality principles restricts removable media access and data classification enforcement, limiting what data adversaries can collect from physical media on compromised endpoints."},{"id":"T1041","name":"Exfiltration Over C2 Channel","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Defense-in-depth networking principles layer egress filtering, protocol inspection, and data loss prevention, making C2-based exfiltration detectable even when one control is circumvented."},{"id":"T1048","name":"Exfiltration Over Alternative Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Security engineering principles ensure multiple layers of egress control across protocols, preventing adversaries from discovering a single alternative protocol channel for undetected exfiltration."},{"id":"T1052","name":"Exfiltration Over Physical Medium","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Least-functionality principles disable unnecessary removable media interfaces and enforce physical port controls, reducing the channels available for physical-medium data exfiltration."},{"id":"T1078","name":"Valid Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Engineering systems with least privilege, separation of duties, and defense in depth reduces the impact of valid credential compromise by ensuring no single account provides unrestricted access."},{"id":"T1190","name":"Exploit Public-Facing Application","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Secure engineering principles including input validation, least privilege, and fail-secure design reduce the exploitable vulnerability surface of public-facing applications."},{"id":"T1482","name":"Domain Trust Discovery","tactics":["discovery"],"mapping_type":"mitigates","mapping_rationale":"Security engineering principles of minimal trust and network segmentation limit domain trust relationships, preventing adversaries from discovering and exploiting excessive cross-domain trust paths."},{"id":"T1567","name":"Exfiltration Over Web Service","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Defense-in-depth principles layer DLP inspection, URL filtering, and cloud access security at multiple points, preventing adversaries from exfiltrating data through web services even if one layer fails."},{"id":"T1647","name":"Plist File Modification","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Secure engineering of macOS application configurations with integrity verification and restricted plist modification prevents adversaries from tampering with property list files for persistence."},{"id":"T1048.002","name":"Exfiltration Over Asymmetric Encrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Engineering redundant inspection layers for encrypted outbound traffic (TLS interception, metadata analysis, behavioral detection) prevents adversaries from exfiltrating data through encrypted non-C2 channels."},{"id":"T1048.003","name":"Exfiltration Over Unencrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Layered security engineering ensures unencrypted protocol channels are subject to content inspection and DLP at multiple enforcement points, preventing plaintext data exfiltration."},{"id":"T1052.001","name":"Exfiltration over USB","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Security engineering principles apply physical port control, device authentication, and data classification enforcement to USB interfaces, blocking unauthorized data transfer to removable drives."},{"id":"T1078.001","name":"Default Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Secure-by-default engineering ensures systems ship without active default accounts and with changed default credentials, eliminating the known credential attack surface that adversaries target."},{"id":"T1078.003","name":"Local Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Applying least privilege and separation of duties to local account design ensures that compromised local credentials provide minimal access, limiting adversary persistence and escalation."},{"id":"T1078.004","name":"Cloud Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Engineering cloud environments with least-privilege IAM policies, mandatory MFA, and conditional access ensures compromised cloud credentials have minimal blast radius."},{"id":"T1134.005","name":"SID-History Injection","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Engineering Active Directory with clean SID-History hygiene, forest trust boundaries, and privilege separation prevents adversaries from exploiting SID injection for cross-domain privilege escalation."},{"id":"T1213.003","name":"Code Repositories","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Security engineering of code repository access with branch protections, mandatory code review, and secret scanning prevents adversaries from accessing sensitive source code and embedded credentials."},{"id":"T1559.003","name":"XPC Services","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Secure engineering of macOS XPC services with proper entitlement validation and connection authentication prevents adversaries from exploiting insecure inter-process communication for privilege escalation."},{"id":"T1574.002","name":"DLL Side-Loading","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Secure engineering principles mandate signed DLL verification, hardened search paths, and application isolation, preventing adversaries from exploiting side-loading vulnerabilities for code injection."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: iso_27001_2022 A.8.28 added from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR entry 155), which OSA's mapping now takes as its base. 2026-10-03: nist_csf_2 ID.AM-08, ID.IM-01, ID.IM-02, ID.IM-03, PR.DS-10, PR.IR-03 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-001","SP-002","SP-004","SP-008","SP-012","SP-017","SP-025","SP-027","SP-028","SP-029","SP-030","SP-032","SP-033","SP-034","SP-039","SP-040","SP-045","SP-047","SP-048","SP-050"]}}