Example: marketing

Engineering Trustworthy Secure Systems - NIST

NIST Special Publication NIST SP 800-160v1r1. Engineering Trustworthy Secure Systems Ron Ross Mark Winstead Michael McEvilley This publication is available free of charge from: NIST Special Publication NIST SP 800-160v1r1. Engineering Trustworthy Secure Systems Ron Ross Computer Security Division Information Technology Laboratory Mark Winstead Michael McEvilley The MITRE Corporation This publication is available free of charge from: November 2022. Department of Commerce Gina M. Raimondo, Secretary National Institute of Standards and Technology Laurie E. Locascio, NIST Director and Under Secretary of Commerce for Standards and Technology NIST SP 800-160v1r1 Engineering Trustworthy Secure Systems November 2022. Certain commercial entities, equipment, or materials may be identified in this document in order to describe an experimental procedure or concept adequately. Such identification is not intended to imply recommendation or endorsement by the National Institute of Standards and Technology (NIST), nor is it intended to imply that the entities, materials, or equipment are necessarily the best available for the purpose.

NIST SP 800-160v1r1 Engineering Trustworthy Secure Systems November 2022 . i . Abstract . This publication describes a basis for establishing principles, concepts, activities, and tasks for engineering trustworthy secure systems. Such principles, concepts, activities, and tasks can be

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of Engineering Trustworthy Secure Systems - NIST

1 NIST Special Publication NIST SP 800-160v1r1. Engineering Trustworthy Secure Systems Ron Ross Mark Winstead Michael McEvilley This publication is available free of charge from: NIST Special Publication NIST SP 800-160v1r1. Engineering Trustworthy Secure Systems Ron Ross Computer Security Division Information Technology Laboratory Mark Winstead Michael McEvilley The MITRE Corporation This publication is available free of charge from: November 2022. Department of Commerce Gina M. Raimondo, Secretary National Institute of Standards and Technology Laurie E. Locascio, NIST Director and Under Secretary of Commerce for Standards and Technology NIST SP 800-160v1r1 Engineering Trustworthy Secure Systems November 2022. Certain commercial entities, equipment, or materials may be identified in this document in order to describe an experimental procedure or concept adequately. Such identification is not intended to imply recommendation or endorsement by the National Institute of Standards and Technology (NIST), nor is it intended to imply that the entities, materials, or equipment are necessarily the best available for the purpose.

2 There may be references in this publication to other publications currently under development by NIST in accordance with its assigned statutory responsibilities. The information in this publication, including concepts and methodologies, may be used by federal agencies even before the completion of such companion publications. Thus, until each publication is completed, current requirements, guidelines, and procedures, where they exist, remain operative. For planning and transition purposes, federal agencies may wish to closely follow the development of these new publications by NIST. Organizations are encouraged to review all draft publications during public comment periods and provide feedback to NIST. Many NIST cybersecurity publications, other than the ones noted above, are available at Authority This publication has been developed by NIST in accordance with its statutory responsibilities under the Federal Information Security Modernization Act (FISMA) of 2014, 44 3551 et seq.

3 , Public Law ( ) 113-283. NIST is responsible for developing information security standards and guidelines, including minimum requirements for federal information Systems , but such standards and guidelines shall not apply to national security Systems without the express approval of appropriate federal officials exercising policy authority over such Systems . This guideline is consistent with the requirements of the Office of Management and Budget (OMB) Circular A-130. Nothing in this publication should be taken to contradict the standards and guidelines made mandatory and binding on federal agencies by the Secretary of Commerce under statutory authority. Nor should these guidelines be interpreted as altering or superseding the existing authorities of the Secretary of Commerce, Director of the OMB, or any other federal official. This publication may be used by nongovernmental organizations on a voluntary basis and is not subject to copyright in the United States.

4 Attribution would, however, be appreciated by NIST. NIST Technical Series Policies Copyright, Fair Use, and Licensing Statements NIST Technical Series Publication Identifier Syntax Publication History Approved by the NIST Editorial Review Board on 2022-11-08. Supersedes NIST SP 800-160 Vol. 1 (Nov. 2016; updated 2018-03-21) How to Cite this NIST Technical Series Publication: Ross R, McEvilley M, Winstead M (2022) Engineering Trustworthy Secure Systems . (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) NIST SP 800-160v1r1. Author ORCID iDs Ron Ross: 0000-0002-1099-9757. Contact Information National Institute of Standards and Technology Attn: Computer Security Division, Information Technology Laboratory 100 Bureau Drive (Mail Stop 8930) Gaithersburg, MD 20899-8930. All comments are subject to release under the Freedom of Information Act (FOIA). NIST SP 800-160v1r1 Engineering Trustworthy Secure Systems November 2022.

5 Abstract This publication describes a basis for establishing principles, concepts, activities, and tasks for Engineering Trustworthy Secure Systems . Such principles, concepts, activities, and tasks can be effectively applied within Systems Engineering efforts to foster a common mindset to deliver security for any system, regardless of the system's purpose, type, scope, size, complexity, or the stage of its system life cycle. The intent of this publication is to advance Systems Engineering in developing Trustworthy Systems for contested operational environments (generally referred to as Systems security Engineering ) and to serve as a basis for developing educational and training programs, professional certifications, and other assessment criteria. Keywords assurance; developmental Engineering ; Engineering trades; field Engineering ; implementation;. information security; information security policy; inspection; integration; penetration testing.

6 Protection needs; requirements analysis; resilience; review; risk assessment; risk management;. risk treatment; security architecture; security design; security requirements; specifications;. stakeholders; system of Systems ; system component; system element; system life cycle; Systems ;. Systems Engineering ; Systems security Engineering ; trustworthiness; validation; verification Reports on Computer Systems Technology The Information Technology Laboratory (ITL) at the National Institute of Standards and Technology (NIST) promotes the economy and public welfare by providing technical leadership for the Nation's measurement and standards infrastructure. ITL develops tests, test methods, reference data, proof of concept implementations, and technical analyses to advance the development and productive use of information technology. ITL's responsibilities include the development of management, administrative, technical, and physical standards and guidelines for the cost-effective security and privacy of other than national security-related information in federal information Systems .

7 The Special Publication 800-series reports on ITL's research, guidelines, and outreach efforts in information system security, and its collaborative activities with industry, government, and academic organizations. i NIST SP 800-160v1r1 Engineering Trustworthy Secure Systems November 2022. Patent Disclosure Notice NOTICE: ITL has requested that holders of patent claims whose use may be required for compliance with the guidance or requirements of this publication disclose such patent claims to ITL. However, holders of patents are not obligated to respond to ITL calls for patents and ITL. has not undertaken a patent search in order to identify which, if any, patents may apply to this publication. As of the date of publication and following call(s) for the identification of patent claims whose use may be required for compliance with the guidance or requirements of this publication, no such patent claims have been identified to ITL. No representation is made or implied by ITL that licenses are not required to avoid patent infringement in the use of this publication.

8 Disclaimer This publication should be used as a supplement to International Standard ISO/IEC/IEEE. 15288 and other supporting international standards. It is recommended that organizations using this publication obtain the appropriate international standards to understand the context of the material in Appendices G through K. Content from ISO/IEC/IEEE 15288 referenced in this publication is used with permission from the Institute of Electrical and Electronics Engineers. It is noted as follows: Reprinted with permission from IEEE, Copyright IEEE 2015, All rights reserved. The reprinted material has been updated to reflect any changes in the international standard. ii NIST SP 800-160v1r1 Engineering Trustworthy Secure Systems November 2022. Table of Contents Introduction .. 1. Purpose and Applicability .. 2. Target Audience .. 4. How to Use this Publication .. 5. Organization of this Publication .. 5. Systems Engineering Overview.

9 7. System 7. Systems and System 7. Interfacing, Enabling, and Interoperating Systems .. 8. Systems Engineering Foundations .. 9. Trust and Trustworthiness .. 10. System Security Concepts .. 12. The Concept of Security .. 12. The Concept of an Adequately Secure System .. 13. Characteristics of Systems .. 16. The Concept of Assets .. 16. The Concepts of Loss and Loss Control .. 18. Reasoning about Asset Loss .. 20. Determining Protection Needs .. 25. System Security Viewpoints .. 27. Demonstrating System Security .. 28. Systems Security Engineering .. 29. Systems Security Engineering Framework .. 32. The Problem Context .. 33. The Solution Context .. 34. The Trustworthiness Context .. 35. References .. 37. Appendix A. Acronyms .. 47. Appendix B. Glossary .. 49. Appendix C. Security Policy and Requirements .. 64. Security Policy .. 64. Security Requirements .. 65. Distinguishing Requirements, Policy, and Mechanisms .. 68. Appendix D.

10 Trustworthy Secure Design .. 70. Design Approach for Trustworthy Systems .. 70. iii NIST SP 800-160v1r1 Engineering Trustworthy Secure Systems November 2022. Design Considering Emergence .. 73. Security Design Order of Precedence .. 74. Functional Design Considerations .. 76. Appendix E. Principles for Trustworthy Secure Design .. 82. Anomaly 83. Clear Abstractions .. 85. Commensurate Protection .. 85. Commensurate Response .. 85. Commensurate 86. Commensurate Trustworthiness .. 87. Compositional 87. Continuous Protection .. 87. Defense In Depth .. 88. Distributed Privilege .. 89. Diversity (Dynamicity) .. 89. Domain Separation .. 90. Hierarchical 91. Least Functionality .. 91. Least Persistence .. 92. Least Privilege .. 93. Least 93. Loss Margins .. 94. Mediated Access .. 94. Minimal Trusted Elements .. 95. Minimize Detectability .. 96. Protective 96. Protective Failure .. 96. Protective 97. Reduced 97. 98. Self-Reliant Trustworthiness.


Related search queries