# SA-08 Security and Privacy Engineering Principles

NIST SP 800-53 control. Family: SA System and Services Acquisition. Function: preventative. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: Apply the following systems security and privacy engineering principles in the specification, design, development, implementation, and modification of the system and system components: [Assignment: organization-defined systems security and privacy engineering principles].
Guidance: Systems security and privacy engineering principles are closely related to and implemented throughout the system development life cycle (see SA-03). Organizations can apply systems security and privacy engineering principles to new systems under development or to systems undergoing upgrades. For existing systems, organizations apply systems security and privacy engineering principles to system upgrades and modifications to the extent feasible, given the current state of hardware, software, and firmware components within those systems. The application of systems security and privacy engineering principles helps organizations develop trustworthy, secure, and resilient systems and reduces the susceptibility to disruptions, hazards, threats, and the creation of privacy problems for individuals. Examples of system security and privacy engineering principles include: developing layered protections; establishing security and privacy policies, architecture, and controls as the foundation for design and development; incorporating security and privacy requirements into the system development life cycle; delineating physical and logical security boundaries; ensuring that developers are trained on how to build secure software; tailoring controls to meet organizational needs; and performing threat modeling to identify use cases, threat agents, attack vectors and patterns, design patterns, and compensating controls needed to mitigate risk. Organizations that apply systems security and privacy engineering concepts and principles can facilitate the development of trustworthy, secure systems, system components, and system services; reduce risk to acceptable levels; and make informed risk management decisions. System security engineering principles can also be used to protect against certain supply chain risks, including incorporating tamper-resistant hardware into a design.

## Enhancements (33)
- SA-08(01) Clear Abstractions
- SA-08(02) Least Common Mechanism
- SA-08(03) Modularity and Layering
- SA-08(04) Partially Ordered Dependencies
- SA-08(05) Efficiently Mediated Access
- SA-08(06) Minimized Sharing
- SA-08(07) Reduced Complexity
- SA-08(08) Secure Evolvability
- SA-08(09) Trusted Components
- SA-08(10) Hierarchical Trust
- SA-08(11) Inverse Modification Threshold
- SA-08(12) Hierarchical Protection
- SA-08(13) Minimized Security Elements
- SA-08(14) Least Privilege
- SA-08(15) Predicate Permission
- SA-08(16) Self-reliant Trustworthiness
- SA-08(17) Secure Distributed Composition
- SA-08(18) Trusted Communications Channels
- SA-08(19) Continuous Protection
- SA-08(20) Secure Metadata Management
- SA-08(21) Self-analysis
- SA-08(22) Accountability and Traceability
- SA-08(23) Secure Defaults
- SA-08(24) Secure Failure and Recovery
- SA-08(25) Economic Security
- SA-08(26) Performance Security
- SA-08(27) Human Factored Security
- SA-08(28) Acceptable Security
- SA-08(29) Repeatable and Documented Procedures
- SA-08(30) Procedural Rigor
- SA-08(31) Secure System Modification
- SA-08(32) Sufficient Documentation
- SA-08(33) Minimization. Baselines: privacy
Each enhancement's statement: /api/v1/controls/SA-08?fields=enhancements

## Patterns that use it (20)
- Critical (3): SP-012 Secure Software Development Lifecycle; SP-034 Cyber Resilience; SP-039 Client-Side Encryption and Data Privacy
- Important (14): SP-008 Public Web Server Pattern; SP-017 Secure Network Zone Module; SP-025 Advanced Monitoring and Detection; SP-027 Secure LLM Usage; SP-028 Secure DevOps Pipeline Pattern; SP-029 Zero Trust Architecture; SP-030 API Security; SP-032 Modern Authentication; SP-033 Passkey Authentication; SP-040 Post-Quantum Cryptography and Quantum Readiness; SP-045 AI Governance and Responsible AI; SP-047 Secure Agentic AI Frameworks; SP-048 Offensive AI and Deepfake Defence (draft); SP-050 Mobile Security Architecture (draft)
- Standard (3): SP-001 Client Module; SP-002 Server Module; SP-004 SOA Publication and Location Pattern

## Clauses by framework (68 frameworks)
- iso_27001_2022: A.8.25, A.8.26, A.8.27, A.8.28. OSA's own, not in NIST's crosswalk: A.8.25, A.8.26
- iso_27002_2022: 5.8, 8.25, 8.26, 8.27
- cobit_2019: APO03, APO04, BAI02, BAI03
- pci_dss_v4: 6.2
- nist_csf_2: ID.AM-08, ID.IM-01, ID.IM-02, ID.IM-03, PR.DS-10, PR.IR-03, PR.PS-06
- cis_controls_v8: CIS 16, CIS 16.10, CIS 16.11, CIS 16.14
- soc2_tsc: CC2.2, CC3.2, CC5.1, CC5.2, CC6.1-POF2, CC6.1-POF7, CC6.7-POF1, CC7.1, CC7.1-POF1, CC8.1
- iso_42001_2023: A.6.1.2, A.6.1.3
- nis2: Art. 21(2)(e)
- mas_trm: 5, 6
- anssi: Hygiene.23, Hygiene.36, SecNumCloud.15.3
- osfi_b13: B-13.2.2, B-13.3.2
- finma_circular: IV.A(28), IV.A(29), IV.B.d(59)
- gdpr: Art.25(1), Art.25(2), Rec.78
- dora: Art.7(1), Art.9(1)
- bio2: 5.8, 8.25, 8.26, 8.27
- rbi_csf: Annex1.6, ITGRCA.12
- fisc: FISC.O10, FISC.O13, FISC.T1, FISC.T6
- hkma_tme1: TME1.3.1, TME1.3.2, TME1.7.3
- mlps_2: 8.1.9.4
- dnb_good_practice: DNB.2.1, DNB.3.2
- cra: CRA.I.1, CRA.I.2b, CRA.I.2g, CRA.I.2j
- cbb_tm: TM-7
- cbuae: CR-6
- nca_ecc: 1-6, 2-3, 2-14, 5-1
- qatar_nia: SD
- sama_csf: 1.4, 3.2
- uae_ia: T10
- bog_cisd: CISD-IX, CISD-SDLC
- bom_ctrm: 3.1, 3.11
- cbe_csf: CTO-4
- cbn_csf: Part4, Part5.1, Part5.2
- sa_js2: JS2-SA
- bcbs_239: Principle 2, Principle 6
- bot_cyber: Ch2.5, Ch6.2
- cpmi_pfmi: PFMI.P3, PFMI.P17
- eba_ict: 3.4.4, 3.6.1, 3.6.2
- ecb_croe: CROE.2.3.4
- ffiec_is: II.C.2, II.C.3, II.C.17
- iosco_cyber: LE-3, PROT-6
- nydfs_500: 500.8
- sebi_cscrf: PR.AS, PR.IP
- cmmc_2: SC
- tsa_psd: SD-2 Sec F
- ieee_1686: 5.10
- doe_c2m2: ARCHITECTURE
- api_1164: Sec 5
- iaea_nss: Sec 5.1
- pci_pts: F
- fips_140: FIPS 140-3 §7.2
- common_criteria: CC Part 1 — PP, CC Part 1 — ST, CC Part 3 — SAR
- fca_sysc_13: SYSC 13.7.1, SYSC 13.8.4
- fda_21_cfr_11: §11.10(a)
- fda_cyber: SPDF-1, SPDF-3, TM-2, TM-3
- hitrust_csf: 09.b, 10.a, 10.d
- iso_27799: 14.1, 14.2
- lloyds_ms: BP2.1, MS1.1
- naic_ds: 4-config
- pra_ss1_23: P3.1
- solvency_ii: EIOPA-ICT-4.11
- owasp_masvs_v2: MASVS-CRYPTO-1, MASVS-CRYPTO-2, MASVS-PRIVACY-2, MASVS-RESILIENCE-2, MASVS-RESILIENCE-3, MASVS-RESILIENCE-4
- csa_ccm_v4: AIS-01, AIS-02, AIS-04, DSP-07
- csa_aicm: AIS-01, AIS-02, AIS-04, AIS-08, AIS-10, AIS-14, AIS-15, DSP-07, DSP-20, MDS-01, MDS-09, MDS-10
- mica: Art.62(5), Art.68(1), Art.68(5), Art.69(1), Art.70(1), Art.72(1)
- basel_sco60: SCO60.2, SCO60.14, SCO60.21, SCO60.51, SCO60.52, SCO60.64, SCO60.65
- bssc: KMS-02, TIS-03
- sec_custody_digital: SEC-CD-03, SEC-CD-06, SEC-CD-08
- dpdpa: Act.6(1), Act.8(4), Rules.Sch2
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/SA-08
- Clauses only: /api/v1/controls/SA-08?fields=mappings
- Page for people: /controls/sa-08/
