Example: quiz answers

Engineering Trustworthy Secure Systems

Withdrawn Draft Warning Notice The attached draft document has been withdrawn, and is provided solely for historical purposes. It has been superseded by the document identified below. Withdrawal Date June 7, 2022 Original Release Date January 11, 2022 Superseding Document Status Final Public Draft (fpd) Series/Number NIST SP 800-160v1r1 fpd Title Engineering Trustworthy Secure Systems Publication Date June 7, 2022 DOI CSRC URL Additional Information Draft NIST Special Publication 800-160, Volume 1 Revision 1 Engineering Trustworthy Secure Systems RON ROSS MICHAEL McEVILLEY MARK WINSTEAD This publication is available free of charge from: Draft NIST Special Publication 800-160, Volume 1 Revision 1 Engineering Trustworthy Secure Systems RON ROSS Computer Security Division Information Technology Laboratory MICHAEL McEVILLEY MARK WINSTEAD The MITRE Corporation McLean, VA This publication is available free of charge from.

This update to SP 800-160, Volume 1 provided an excellent opportunity to reflect on the past 93 five years of the publication’s use by systems engineers and systems security engineers and to 94 apply targeted lessons learned during that timeframe. In particular, we focused on the following

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of Engineering Trustworthy Secure Systems

1 Withdrawn Draft Warning Notice The attached draft document has been withdrawn, and is provided solely for historical purposes. It has been superseded by the document identified below. Withdrawal Date June 7, 2022 Original Release Date January 11, 2022 Superseding Document Status Final Public Draft (fpd) Series/Number NIST SP 800-160v1r1 fpd Title Engineering Trustworthy Secure Systems Publication Date June 7, 2022 DOI CSRC URL Additional Information Draft NIST Special Publication 800-160, Volume 1 Revision 1 Engineering Trustworthy Secure Systems RON ROSS MICHAEL McEVILLEY MARK WINSTEAD This publication is available free of charge from: Draft NIST Special Publication 800-160, Volume 1 Revision 1 Engineering Trustworthy Secure Systems RON ROSS Computer Security Division Information Technology Laboratory MICHAEL McEVILLEY MARK WINSTEAD The MITRE Corporation McLean, VA This publication is available free of charge from: January 2022 Department of Commerce Gina M.

2 Raimondo, Secretary National Institute of Standards and Technology James K. Olthoff, Performing the Non-Exclusive Functions and Duties of the Under Secretary of Commerce for Standards and Technology & Director, National Institute of Standards and Technology NIST SP 800-160, VOL. 1, REV. 1 (DRAFT) Engineering Trustworthy Secure Systems _____ AUTHORITY 1 This publication has been developed by NIST to further its statutory responsibilities under the 2 Federal Information Security Modernization Act (FISMA), 44 3551 et seq., Public Law 3 ( ) 113-283. NIST is responsible for developing information security standards and guidelines, 4 including minimum requirements for federal information Systems , but such standards and 5 guidelines shall not apply to national security Systems without the express approval of the 6 appropriate federal officials exercising policy authority over such Systems .

3 This guideline is 7 consistent with requirements of the Office of Management and Budget (OMB) Circular A-130. 8 Nothing in this publication should be taken to contradict the standards and guidelines made 9 mandatory and binding on federal agencies by the Secretary of Commerce under statutory 10 authority. Nor should these guidelines be interpreted as altering or superseding the existing 11 authorities of the Secretary of Commerce, OMB Director, or any other federal official. This 12 publication may be used by nongovernmental organizations on a voluntary basis and is not 13 subject to copyright in the United States. Attribution would, however, be appreciated by NIST. 14 National Institute of Standards and Technology Special Publication 800-160, Vol. 1, Rev. 1 15 Natl. Inst. Stand.

4 Technol. Spec. Publ. 800-160, Vol. 1, Rev. 1, 207 pages (January 2022) 16 CODEN: NSPUE2 17 This publication is available free of charge from: 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 Public comment period: January 11, 2022 February 25, 2022 34 Submit comments on this publication to: 35 National Institute of Standards and Technology 36 Attn: Computer Security Division, Information Technology Laboratory 37 100 Bureau Drive (Mail Stop 8930) Gaithersburg, MD 20899-8930 38 All comments are subject to release under the Freedom of Information Act (FOIA) [FOIA96]. 39 Certain commercial entities, equipment, or materials may be identified in this document to describe an experimental procedure or concept adequately. Such identification is not intended to imply recommendation or endorsement by NIST, nor is it intended to imply that the entities, materials, or equipment are necessarily the best available for the purpose.

5 There may be references in this publication to other publications currently under development by NIST in accordance with its assigned statutory responsibilities. The information in this publication, including concepts, practices, and methodologies, may be used by federal agencies even before the completion of such companion publications. Thus, until each publication is completed, current requirements, guidelines, and procedures, where they exist, remain operative. For planning and transition purposes, federal agencies may wish to closely follow the development of these new publications by NIST. Organizations are encouraged to review draft publications during the public comment periods and provide feedback to NIST. Many NIST publications, other than the ones noted above, are available at NIST SP 800-160, VOL.

6 1, REV. 1 (DRAFT) Engineering Trustworthy Secure Systems _____ REPORTS ON COMPUTER Systems TECHNOLOGY 40 The National Institute of Standards and Technology (NIST) Information Technology Laboratory 41 (ITL) promotes the economy and public welfare by providing technical leadership for the 42 Nation s measurement and standards infrastructure. ITL develops tests, test methods, reference 43 data, proof of concept implementations, and technical analyses to advance the development 44 and productive use of information technology (IT). ITL s responsibilities include the development 45 of management, administrative, technical, and physical standards and guidelines for the cost-46 effective security of other than national security-related information in federal information 47 Systems .

7 The Special Publication 800-series reports on ITL s research, guidelines, and outreach 48 efforts in information Systems security and privacy and its collaborative activities with industry, 49 government, and academic organizations. 50 ABSTRACT 51 With the continuing frequency, intensity, and adverse consequences of cyber-attacks, 52 disruptions, hazards, and other threats to federal, state, and local governments, as well as 53 private sector organizations, the need for Trustworthy Secure Systems has never been more 54 important to the long-term economic and national security interests of the United States. 55 Engineering -based solutions are essential to managing the complexity, dynamicity, and 56 interconnectedness of today s Systems , as exemplified by cyber-physical Systems and Systems -57 of- Systems .

8 This publication addresses the Engineering -driven perspective and actions necessary 58 to develop more defensible and survivable Systems , inclusive of the machine, physical, and 59 human components that compose those Systems and the capabilities and services delivered by 60 those Systems . This publication starts with and builds upon established international standards 61 for Systems and software Engineering by the International Organization for Standardization 62 (ISO), the International Electrotechnical Commission (IEC), and the Institute of Electrical and 63 Electronics Engineers (IEEE) and infuses Systems security Engineering methods, practices, and 64 techniques into those Systems and software Engineering activities. The objective is to address 65 security issues from a stakeholder protection needs, concerns, and requirements perspective 66 and to use established Engineering processes to help ensure that such needs, concerns, and 67 requirements are addressed with appropriate fidelity and rigor throughout the system life cycle.

9 68 KEYWORDS 69 Assurance; developmental Engineering ; disposal; Engineering trades; field Engineering ; 70 implementation; information security; information security policy; inspection; integration; 71 penetration testing; protection needs; requirements analysis; resilience; review; risk 72 assessment; risk management; risk treatment; security architecture; security authorization; 73 security design; security requirements; specifications; stakeholder; system of Systems ; system 74 component; system element; system life cycle; Systems ; Systems Engineering ; Systems security 75 Engineering ; trustworthiness; validation; verification. 76 NIST SP 800-160, VOL. 1, REV. 1 (DRAFT) Engineering Trustworthy Secure Systems _____ ACKNOWLEDGMENTS 77 The authors gratefully acknowledge and appreciate the significant contributions from individuals 78 and organizations in the public and private sectors whose constructive comments improved the 79 overall quality, thoroughness, and usefulness of this publication.

10 In particular, we wish to thank 80 Jeff Brewer, Ken Cureton, Jordan Denmark, Rick Dove, Holly Dunlap, Jim Foti, Michael Hankins, 81 Daryl Hild, M. Lee, Tom Llanso, Jimmie McEver, Perri Nejib, Cory Ocker, Daniel Patrick Pereira, 82 Victoria Pillitteri, Greg Ritter, Thom Schoeffling, Theresa Soloway, Gary Stoneburner, Gregory 83 Touhill, Isabel Van Wyk, Adam Williams, Drew Wilson, Carol Woody, William Young, and Michael 84 Zisa. Finally, the authors wish to thank the students participating in the various INCOSE tutorials 85 and MITRE Systems Security Engineering courses whose comments and insights help guide and 86 inform many of the proposed changes in this publication. 87 88 89 90 HISTORICAL CONTRIBUTIONS The authors gratefully acknowledge the contributions of Janet Carrier Oren, one of the original coauthors of NIST Special Publication 800-160, Volume 1.


Related search queries