← Controls / SA

SA-08 Security and Privacy Engineering Principles

System and Services Acquisition

Low Moderate High

Description

Apply the following systems security and privacy engineering principles in the specification, design, development, implementation, and modification of the system and system components: [Assignment: organization-defined systems security and privacy engineering principles].

Supplemental Guidance

Systems security and privacy engineering principles are closely related to and implemented throughout the system development life cycle (see SA-03). Organizations can apply systems security and privacy engineering principles to new systems under development or to systems undergoing upgrades. For existing systems, organizations apply systems security and privacy engineering principles to system upgrades and modifications to the extent feasible, given the current state of hardware, software, and firmware components within those systems. The application of systems security and privacy engineering principles helps organizations develop trustworthy, secure, and resilient systems and reduces the susceptibility to disruptions, hazards, threats, and the creation of privacy problems for individuals. Examples of system security and privacy engineering principles include: developing layered protections; establishing security and privacy policies, architecture, and controls as the foundation for design and development; incorporating security and privacy requirements into the system development life cycle; delineating physical and logical security boundaries; ensuring that developers are trained on how to build secure software; tailoring controls to meet organizational needs; and performing threat modeling to identify use cases, threat agents, attack vectors and patterns, design patterns, and compensating controls needed to mitigate risk. Organizations that apply systems security and privacy engineering concepts and principles can facilitate the development of trustworthy, secure systems, system components, and system services; reduce risk to acceptable levels; and make informed risk management decisions. System security engineering principles can also be used to protect against certain supply chain risks, including incorporating tamper-resistant hardware into a design.

Changes from Rev 4

Title changed from 'Security Engineering Principles' Control text adds privacy and system components New parameter requires specifying applicable systems security and privacy engineering principles Discussion expanded to explain benefits Incorporates withdrawn control SA-13

Enhancements (33)

What NIST adds to this control. Select one to read its statement.

SA-08(01) Clear Abstractions

Implement the security design principle of clear abstractions.

SA-08(02) Least Common Mechanism

Implement the security design principle of least common mechanism in [Assignment: organization-defined systems or system components].

SA-08(03) Modularity and Layering

Implement the security design principles of modularity and layering in [Assignment: organization-defined systems or system components].

SA-08(04) Partially Ordered Dependencies

Implement the security design principle of partially ordered dependencies in [Assignment: organization-defined systems or system components].

SA-08(05) Efficiently Mediated Access

Implement the security design principle of efficiently mediated access in [Assignment: organization-defined systems or system components].

SA-08(06) Minimized Sharing

Implement the security design principle of minimized sharing in [Assignment: organization-defined systems or system components].

SA-08(07) Reduced Complexity

Implement the security design principle of reduced complexity in [Assignment: organization-defined systems or system components].

SA-08(08) Secure Evolvability

Implement the security design principle of secure evolvability in [Assignment: organization-defined systems or system components].

SA-08(09) Trusted Components

Implement the security design principle of trusted components in [Assignment: organization-defined systems or system components].

SA-08(10) Hierarchical Trust

Implement the security design principle of hierarchical trust in [Assignment: organization-defined systems or system components].

SA-08(11) Inverse Modification Threshold

Implement the security design principle of inverse modification threshold in [Assignment: organization-defined systems or system components].

SA-08(12) Hierarchical Protection

Implement the security design principle of hierarchical protection in [Assignment: organization-defined systems or system components].

SA-08(13) Minimized Security Elements

Implement the security design principle of minimized security elements in [Assignment: organization-defined systems or system components].

SA-08(14) Least Privilege

Implement the security design principle of least privilege in [Assignment: organization-defined systems or system components].

SA-08(15) Predicate Permission

Implement the security design principle of predicate permission in [Assignment: organization-defined systems or system components].

SA-08(16) Self-reliant Trustworthiness

Implement the security design principle of self-reliant trustworthiness in [Assignment: organization-defined systems or system components].

SA-08(17) Secure Distributed Composition

Implement the security design principle of secure distributed composition in [Assignment: organization-defined systems or system components].

SA-08(18) Trusted Communications Channels

Implement the security design principle of trusted communications channels in [Assignment: organization-defined systems or system components].

SA-08(19) Continuous Protection

Implement the security design principle of continuous protection in [Assignment: organization-defined systems or system components].

SA-08(20) Secure Metadata Management

Implement the security design principle of secure metadata management in [Assignment: organization-defined systems or system components].

SA-08(21) Self-analysis

Implement the security design principle of self-analysis in [Assignment: organization-defined systems or system components].

SA-08(22) Accountability and Traceability

Implement the security design principle of accountability and traceability in [Assignment: organization-defined systems or system components].

SA-08(23) Secure Defaults

Implement the security design principle of secure defaults in [Assignment: organization-defined systems or system components].

SA-08(24) Secure Failure and Recovery

Implement the security design principle of secure failure and recovery in [Assignment: organization-defined systems or system components].

SA-08(25) Economic Security

Implement the security design principle of economic security in [Assignment: organization-defined systems or system components].

SA-08(26) Performance Security

Implement the security design principle of performance security in [Assignment: organization-defined systems or system components].

SA-08(27) Human Factored Security

Implement the security design principle of human factored security in [Assignment: organization-defined systems or system components].

SA-08(28) Acceptable Security

Implement the security design principle of acceptable security in [Assignment: organization-defined systems or system components].

SA-08(29) Repeatable and Documented Procedures

Implement the security design principle of repeatable and documented procedures in [Assignment: organization-defined systems or system components].

SA-08(30) Procedural Rigor

Implement the security design principle of procedural rigor in [Assignment: organization-defined systems or system components].

SA-08(31) Secure System Modification

Implement the security design principle of secure system modification in [Assignment: organization-defined systems or system components].

SA-08(32) Sufficient Documentation

Implement the security design principle of sufficient documentation in [Assignment: organization-defined systems or system components].

SA-08(33) Minimization Privacy

Implement the privacy principle of minimization using [Assignment: organization-defined processes].

Compliance Mappings

ISO 27001:2022

A.8.25A.8.26A.8.27A.8.28

ISO 27002:2022

5.88.258.268.27

COBIT 2019

APO03APO04BAI02BAI03

CIS Controls v8

CIS 16CIS 16.10CIS 16.11CIS 16.14

NIST CSF 2.0

ID.AM-08ID.IM-01ID.IM-02ID.IM-03PR.DS-10PR.IR-03PR.PS-06

SOC 2 TSC

CC2.2CC3.2CC5.1CC5.2CC6.1-POF2CC6.1-POF7CC6.7-POF1CC7.1CC7.1-POF1CC8.1

PCI DSS v4.0.1

6.2

CSA CCM v4

AIS-01AIS-02AIS-04DSP-07

CSA AICM v1

AIS-01AIS-02AIS-04AIS-08AIS-10AIS-14AIS-15DSP-07DSP-20MDS-01MDS-09MDS-10

ISO 42001:2023

A.6.1.2A.6.1.3

NIS2 Directive

Art. 21(2)(e)

MAS TRM

56

ANSSI

Hygiene.23Hygiene.36SecNumCloud.15.3

FINMA Circular 2023/1

IV.A(28)IV.A(29)IV.B.d(59)

OSFI B-13

B-13.2.2B-13.3.2

EU GDPR

Art.25(1)Art.25(2)Rec.78

EU DORA

Art.7(1)Art.9(1)

BIO2

5.88.258.268.27

RBI CSF

Annex1.6ITGRCA.12

FISC Security Guidelines

FISC.O10FISC.O13FISC.T1FISC.T6

HKMA TM-E-1

TME1.3.1TME1.3.2TME1.7.3

MLPS 2.0

8.1.9.4

DNB Good Practice

DNB.2.1DNB.3.2

EU CRA

CRA.I.1CRA.I.2bCRA.I.2gCRA.I.2j

SAMA CSF

1.43.2

NCA ECC

1-62-32-145-1

UAE IA

T10

CBB TM

TM-7

Qatar NIA

SD

CBUAE

CR-6

CBE CSF

CTO-4

SA JS2

JS2-SA

CBN CSF

Part4Part5.1Part5.2

BoG CISD

CISD-IXCISD-SDLC

BoM CTRM

3.13.11

IOSCO Cyber Resilience

LE-3PROT-6

BCBS 239

Principle 2Principle 6

CPMI-IOSCO PFMI

PFMI.P3PFMI.P17

FFIEC IS

II.C.2II.C.3II.C.17

NYDFS 500

500.8

ECB CROE

CROE.2.3.4

EBA ICT Guidelines

3.4.43.6.13.6.2

SEBI CSCRF

PR.ASPR.IP

BOT Cyber Resilience

Ch2.5Ch6.2

CMMC 2.0

SC

TSA Pipeline SD

SD-2 Sec F

IEEE 1686-2022

5.10

DOE C2M2 v2.1

ARCHITECTURE

API 1164

Sec 5

IAEA NSS 17-T

Sec 5.1

PCI PTS v6

F

FIPS 140-3

FIPS 140-3 §7.2

Common Criteria

CC Part 1 — PPCC Part 1 — STCC Part 3 — SAR

Solvency II

EIOPA-ICT-4.11

Lloyd's Minimum Standards

BP2.1MS1.1

NAIC Insurance Data Security

4-config

PRA SS1/23

P3.1

FCA SYSC 13

SYSC 13.7.1SYSC 13.8.4

HITRUST CSF v11

09.b10.a10.d

FDA 21 CFR Part 11

§11.10(a)

FDA Cybersecurity Guidance

SPDF-1SPDF-3TM-2TM-3

ISO 27799

14.114.2

OWASP MASVS v2.1

MASVS-CRYPTO-1MASVS-CRYPTO-2MASVS-PRIVACY-2MASVS-RESILIENCE-2MASVS-RESILIENCE-3MASVS-RESILIENCE-4

MiCA

Art.62(5)Art.68(1)Art.68(5)Art.69(1)Art.70(1)Art.72(1)

Basel SCO60

SCO60.2SCO60.14SCO60.21SCO60.51SCO60.52SCO60.64SCO60.65

BSSC Standards

KMS-02TIS-03

SEC Custody (Digital Assets)

SEC-CD-03SEC-CD-06SEC-CD-08

India DPDPA

Act.6(1)Act.8(4)Rules.Sch2

ISO 17799 (legacy)

12.1

COBIT 4.1 (legacy)

AI2.4