CINXE.COM
CSRC Topics - systems security engineering | CSRC
<!DOCTYPE html> <html lang="en-us" xml:lang="en-us"> <head> <meta charset="utf-8" /> <title>CSRC Topics - systems security engineering | CSRC</title> <meta http-equiv="content-type" content="text/html; charset=UTF-8" /> <meta http-equiv="content-style-type" content="text/css" /> <meta http-equiv="content-script-type" content="text/javascript" /> <meta name="viewport" content="width=device-width, initial-scale=1.0" /> <meta name="msapplication-config" content="/CSRC/Media/images/favicons/browserconfig.xml" /> <meta name="theme-color" content="#000000" /> <meta name="google-site-verification" content="xbrnrVYDgLD-Bd64xHLCt4XsPXzUhQ-4lGMj4TdUUTA" /> <meta name="description" content="Use these CSRC Topics to identify and learn more about NIST's cybersecurity Projects, Publications, News, Events and Presentations." /> <meta name="dcterms.title" content="CSRC Topic: systems security engineering | CSRC"/> <meta name="dcterms.description" content="Use these CSRC Topics to identify and learn more about NIST's cybersecurity Projects, Publications, News, Events and Presentations."/> <meta name="dcterms.creator" content="Computer Security Division, Information Technology Laboratory, National Institute of Standards and Technology, U.S. Department of Commerce"/> <meta name="dcterms.date.created" scheme="ISO8601" content="2016-06-20"/> <meta name="dcterms.date.reviewed" scheme="ISO8601" content="2020-06-22"/> <meta name="dcterms.language" scheme="DCTERMS.RFC1766" content="EN-US"/> <!-- Facebook OpenGraph Tags --> <meta name="og:site_name" content="CSRC | NIST" /> <meta name="og:type" content="article" /> <meta name="og:url" content="https://csrc.nist.gov/topics/security-and-privacy/systems-security-engineering" /> <meta name="og:title" content="CSRC Topic: systems security engineering | CSRC" /> <meta name="og:description" content="Use these CSRC Topics to identify and learn more about NIST's cybersecurity Projects, Publications, News, Events and Presentations." /> <meta name="article:tag" content="systems security engineering" /> <meta name="article:published_time" content="2016-06-20" /> <meta name="article:modified_time" content="2020-06-22"/> <link rel="apple-touch-icon" sizes="180x180" href="/images/icons/apple-touch-icon.png" /> <link rel="icon" type="image/png" href="/images/icons/favicon-32x32.png" sizes="32x32" /> <link rel="icon" type="image/png" href="/images/icons/favicon-16x16.png" sizes="16x16" /> <link rel="manifest" href="/images/icons/manifest.json" /> <link rel="mask-icon" href="/images/icons/safari-pinned-tab.svg" color="#000000" /> <link href="/CSRC/Media/images/favicons/favicon.ico" type="image/x-icon" rel="shortcut icon" /> <link href="/CSRC/Media/images/favicons/favicon.ico" type="image/x-icon" rel="icon" /> <link href="/dist/app.css" rel="stylesheet" /> <!-- Highlight.js --> <link href="/dist/highlight-js/github.css" rel="stylesheet" /> <!-- USWDS Top --> <link href="/dist/uswds/css/uswds.css" type="text/css" rel="stylesheet" /> <script type="text/javascript" src="/dist/uswds/js/uswds-init.min.js"></script> <!-- reCAPTCHA v3 --> <style> .grecaptcha-badge { visibility: hidden; } </style> <script async type="text/javascript" id="_fed_an_ua_tag" src="https://dap.digitalgov.gov/Universal-Federated-Analytics-Min.js?agency=nist&subagency=csrc&pua=UA-66610693-15&yt=true&exts=xsd,xml,wav,mpg,mpeg,avi,rtf,webm,ogg,ogv,oga,map,otf,eot,svg,ttf,woff"></script> <style id="antiClickjackCss"> body > * { display: none !important; } #antiClickjack { display: block !important; } </style> <noscript> <style id="antiClickjackNoScript"> body > * { display: block !important; } #antiClickjack { display: none !important; } </style> </noscript> <script type="text/javascript" id="antiClickjackScript"> if (self === top) { // no clickjacking var antiClickjack = document.getElementById("antiClickjackCss"); antiClickjack.parentNode.removeChild(antiClickjack); } else { setTimeout(tryForward(), 5000); } function tryForward() { top.location = self.location; } </script> <!-- Google tag (gtag.js) --> <script async src="https://www.googletagmanager.com/gtag/js?id=G-TSQ0PLGJZP"></script> <script> window.dataLayer = window.dataLayer || []; function gtag(){dataLayer.push(arguments);} gtag('js', new Date()); gtag('config', 'G-TSQ0PLGJZP'); </script> <!-- Google Tag Manager --> <script>(function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-MZQC4NCJ');</script> <!-- End Google Tag Manager --> </head> <body> <!-- Google Tag Manager (noscript) --> <noscript><iframe src="https://www.googletagmanager.com/ns.html?id=GTM-MZQC4NCJ" height="0" width="0" style="display:none;visibility:hidden"></iframe></noscript> <!-- End Google Tag Manager (noscript) --> <div id="antiClickjack" style="display: none;"> <strong style="font-size: 1.6rem;">You are viewing this page in an unauthorized frame window.</strong> <p>This is a potential security issue, you are being redirected to <a href="https://csrc.nist.gov">https://csrc.nist.gov</a>.</p> </div> <section class="usa-banner" aria-label="Official website of the United States government"> <div class="usa-accordion"> <header class="usa-banner__header"> <noscript> <p style="font-size: 0.85rem; font-weight: bold;">You have JavaScript disabled. This site requires JavaScript to be enabled for complete site functionality.</p> </noscript> <div class="usa-banner__inner"> <div class="grid-col-auto"> <img aria-hidden="true" class="usa-banner__header-flag" src="/dist/uswds/img/us_flag_small.png" alt=""/> </div> <div class="grid-col-fill tablet:grid-col-auto" aria-hidden="true"> <p class="usa-banner__header-text"> An official website of the United States government </p> <p class="usa-banner__header-action">Here’s how you know</p> </div> <button type="button" class="usa-accordion__button usa-banner__button" aria-expanded="false" aria-controls="gov-banner-default"> <span class="usa-banner__button-text">Here’s how you know</span> </button> </div> </header> <div class="usa-banner__content usa-accordion__content" id="gov-banner-default"> <div class="grid-row grid-gap-lg"> <div class="usa-banner__guidance tablet:grid-col-6"> <img class="usa-banner__icon usa-media-block__img" src="/dist/uswds/img/icon-dot-gov.svg" role="img" alt="" aria-hidden="true"/> <div class="usa-media-block__body"> <p> <strong>Official websites use .gov</strong><br/>A <strong>.gov</strong> website belongs to an official government organization in the United States. </p> </div> </div> <div class="usa-banner__guidance tablet:grid-col-6"> <img class="usa-banner__icon usa-media-block__img" src="/dist/uswds/img/icon-https.svg" role="img" alt="" aria-hidden="true"/> <div class="usa-media-block__body"> <p> <strong>Secure .gov websites use HTTPS</strong><br/>A <strong>lock</strong> ( <span class="icon-lock"> <svg xmlns="http://www.w3.org/2000/svg" width="52" height="64" viewBox="0 0 52 64" class="usa-banner__lock-image" role="img" aria-labelledby="banner-lock-description-default" focusable="false"> <title id="banner-lock-title-default">Lock</title> <desc id="banner-lock-description-default">Locked padlock icon</desc> <path fill="#000000" fill-rule="evenodd" d="M26 0c10.493 0 19 8.507 19 19v9h3a4 4 0 0 1 4 4v28a4 4 0 0 1-4 4H4a4 4 0 0 1-4-4V32a4 4 0 0 1 4-4h3v-9C7 8.507 15.507 0 26 0zm0 8c-5.979 0-10.843 4.77-10.996 10.712L15 19v9h22v-9c0-6.075-4.925-11-11-11z"/> </svg> </span >) or <strong>https://</strong> means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites. </p> </div> </div> </div> </div> </div> </section> <nav id="navbar" class="navbar"> <div id="nist-menu-container" class="container"> <div class="row"> <!-- Brand --> <div class="col-xs-6 col-md-4 navbar-header"> <a class="navbar-brand" href="https://www.nist.gov" target="_blank" id="navbar-brand-image"> <img src="/CSRC/media/images/svg/nist-logo.svg" alt="National Institute of Standards and Technology" width="110" height="30"> </a> </div> <div class="col-xs-6 col-md-8 navbar-nist-logo"> <div class="form-inline hidden-sm hidden-xs"> <form name="site-search" id="site-search-form" action="/search" method="GET"> <label for="search-csrc-query" class="element-invisible">Search</label> <input autocomplete="off" class="form-control" id="search-csrc-query" name="keywords" type="text" size="15" maxlength="128" placeholder="Search CSRC" /> <input type="hidden" name="ipp" value="25" /> <input type="hidden" name="sortBy" value="relevance" /> <input type="hidden" name="showOnly" value="publications,projects,news,events,presentations,glossary,topics" /> <input type="hidden" name="topicsMatch" value="ANY" /> <input type="hidden" name="status" value="Final,Draft" /> <button type="submit" id="search-csrc-submit-btn" class="form-submit"> <span class="element-invisible">Search</span> <i class="fa fa-search"></i> </button> </form> </div> <span id="nvd-menu-button" class="pull-right"> <a href="#" id="nvd-menu-button-link"> <span class="fa fa-bars"></span> <span id="nvd-menu-full-text">CSRC MENU</span> </a> </span> </div> </div> </div> <div class="form-inline hidden-md hidden-lg"> <form name="site-search-mobile" id="site-search-form-mobile" action="/search" method="GET"> <label for="search-csrc-query-mobile" class="element-invisible">Search</label> <input autocomplete="off" class="form-control" id="search-csrc-query-mobile" name="keywords" type="text" size="15" maxlength="128" placeholder="Search CSRC" /> <button type="submit" id="search-csrc-submit-btn-mobile" class="form-submit"> <span class="element-invisible">Search</span> <i class="fa fa-search"></i> </button> </form> </div> <div class="main-menu-row container"> <!-- Collect the nav links, forms, and other content for toggling --> <div id="main-menu-drop" class="col-lg-12" style="display: none;"> <ul> <li><a href="/projects">Projects</a></li> <li> <a href="/publications"> Publications <span class="expander fa fa-plus" id="main-menu-pubs-expander" data-expander-name="publications" data-expanded="false"> <span class="element-invisible">Expand or Collapse</span> </span> </a> <div style="display: none;" class="sub-menu" data-expander-trigger="publications" id="main-menu-pubs-expanded"> <div class="row"> <div class="col-lg-4"> <p><a href="/publications/drafts-open-for-comment">Drafts for Public Comment</a></p> <p><a href="/publications/draft-pubs">All Public Drafts</a></p> <p><a href="/publications/final-pubs">Final Pubs</a></p> <p><a href="/publications/fips">FIPS <small>(standards)</small></a></p> </div> <div class="col-lg-4"> <p><a href="/publications/sp">Special Publications (SP<small>s</small>)</a></p> <p><a href="/publications/ir">IR <small>(interagency/internal reports)</small></a></p> <p><a href="/publications/cswp">CSWP <small>(cybersecurity white papers)</small></a></p> <p><a href="/publications/itl-bulletin">ITL Bulletins</a></p> </div> <div class="col-lg-4"> <p><a href="/publications/project-description">Project Descriptions</a></p> <p><a href="/publications/journal-article">Journal Articles</a></p> <p><a href="/publications/conference-paper">Conference Papers</a></p> <p><a href="/publications/book">Books</a></p> </div> </div> </div> </li> <li> <a href="/topics"> Topics <span class="expander fa fa-plus" id="main-menu-topics-expander" data-expander-name="topics" data-expanded="false"> <span class="element-invisible">Expand or Collapse</span> </span> </a> <div style="display: none;" class="sub-menu" data-expander-trigger="topics" id="main-menu-topics-expanded"> <div class="row"> <div class="col-lg-4"> <p><a href="/Topics/Security-and-Privacy">Security & Privacy</a></p> <p><a href="/Topics/Applications">Applications</a></p> </div> <div class="col-lg-4"> <p><a href="/Topics/Technologies">Technologies</a></p> <p><a href="/Topics/Sectors">Sectors</a></p> </div> <div class="col-lg-4"> <p><a href="/Topics/Laws-and-Regulations">Laws & Regulations</a></p> <p><a href="/Topics/Activities-and-Products">Activities & Products</a></p> </div> </div> </div> </li> <li><a href="/news">News & Updates</a></li> <li><a href="/events">Events</a></li> <li><a href="/glossary">Glossary</a></li> <li> <a href="/about"> About CSRC <span class="expander fa fa-plus" id="main-menu-about-expander" data-expander-name="about" data-expanded="false"> <span class="element-invisible">Expand or Collapse</span> </span> </a> <div style="display: none;" class="sub-menu" data-expander-trigger="about" id="main-menu-about-expanded"> <div class="row"> <div class="col-lg-6"> <p> <strong><a href="/Groups/Computer-Security-Division">Computer Security Division</a></strong><br /> <ul> <li><a href="/Groups/Computer-Security-Division/Cryptographic-Technology">Cryptographic Technology</a></li> <li><a href="/Groups/Computer-Security-Division/Secure-Systems-and-Applications">Secure Systems and Applications</a></li> <li><a href="/Groups/Computer-Security-Division/Security-Components-and-Mechanisms">Security Components and Mechanisms</a></li> <li><a href="/Groups/Computer-Security-Division/Security-Engineering-and-Risk-Management">Security Engineering and Risk Management</a></li> <li><a href="/Groups/Computer-Security-Division/Security-Testing-Validation-and-Measurement">Security Testing, Validation, and Measurement</a></li> </ul> </p> </div> <div class="col-lg-6"> <p> <strong><a href="/Groups/Applied-Cybersecurity-Division">Applied Cybersecurity Division</a></strong><br /> <ul> <li><a href="/Groups/Applied-Cybersecurity-Division/Cybersecurity-and-Privacy-Applications">Cybersecurity and Privacy Applications</a></li> <li><a href="/Groups/Applied-Cybersecurity-Division/National-Cybersecurity-Center-of-Excellence">National Cybersecurity Center of Excellence (NCCoE)</a></li> <li><a href="https://www.nist.gov/nice/">National Initiative for Cybersecurity Education (NICE)</a></li> </ul> </p> <p> <a href="/contact"> Contact Us </a> </p> </div> </div> </div> </li> </ul> </div><!-- /#mobile-nav-container --> </div> </nav> <section id="itl-header" class="has-menu"> <div class="container"> <div class="row"> <div class="col-sm-12 col-md-8"> <div class="hidden-xs hidden-sm" id="itl-header-lg"> <a href="https://www.nist.gov/itl" target="_blank" id="itl-header-link">Information Technology Laboratory</a> </div> <div class="hidden-xs hidden-sm" id="csrc-header-lg"> <a href="/" id="csrc-header-link-lg">Computer Security Resource Center</a> </div> </div> <div class="col-sm-12 col-md-4"> <div class="hidden-xs hidden-sm hidden-md"> <a id="logo-csrc-lg" href="/"><img id="img-logo-csrc-lg" src="/CSRC/Media/images/nist-logo-csrc-white.svg" alt="CSRC Logo" class="csrc-header-logo"></a> </div> <div class="hidden-lg"> <a id="logo-csrc-sm" href="/"><img id="img-logo-csrc-sm" src="/CSRC/Media/images/nist-logo-csrc-white.svg" alt="CSRC Logo" class="csrc-header-logo"></a> </div> </div> </div> </div> </section> <div id="body-section" class="container"> <div class="breadcrumb"> <a href="/topics" class="breadcrumb-link">Topics</a> <a href="/topics/security-and-privacy" class="breadcrumb-link">Security and Privacy</a> </div> <div class="topics-content"> <h1 id="page-name">systems security engineering <small id="page-acronym">SSE</small> </h1> <div class="page-social-buttons" id="page-social-buttons"> <a href="https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fcsrc.nist.gov%2Ftopics%2Fsecurity-and-privacy%2Fsystems-security-engineering" class="social-facebook"><i class="fa fa-facebook fa-fw" aria-hidden="true"></i><span class="sr-only">Share to Facebook</span></a> <a href="https://twitter.com/share?url=https%3A%2F%2Fcsrc.nist.gov%2Ftopics%2Fsecurity-and-privacy%2Fsystems-security-engineering" class="social-twitter"><i class="fa fa-twitter fa-fw" aria-hidden="true"></i><span class="sr-only">Share to Twitter</span></a> <a href="https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fcsrc.nist.gov%2Ftopics%2Fsecurity-and-privacy%2Fsystems-security-engineering&source=csrc.nist.gov" class="social-linked-in"><i class="fa fa-linkedin fa-fw" aria-hidden="true"></i><span class="sr-only">Share to LinkedIn</span></a> <a href="mailto:?subject=csrc.nist.gov&body=Check out this site https://csrc.nist.gov/topics/security-and-privacy/systems-security-engineering" class="social-email"><i class="fa fa-envelope fa-fw" aria-hidden="true"></i><span class="sr-only">Share ia Email</span></a> </div> <div class="row"> <div class="col-md-8 col-sm-12"> <div class="topics-related-list" id="related-proj-list"> <h3><i class="fa fa-folder-o"></i> Related Projects</h3> <div class="related-list-item" id="related-proj-0"> <strong><a href="/Projects/combinatorial-testing-for-ai-enabled-systems" id="related-proj-name-0">Combinatorial Testing for AI-Enabled Systems</a> <small id="related-proj-acronym-0">CT4AIES</small></strong><br/> <span id="related-proj-overview-0">The goal of this project is to provide practitioners and researchers with a foundational...</span> </div> <div class="related-list-item" id="related-proj-1"> <strong><a href="/Projects/cyber-supply-chain-risk-management" id="related-proj-name-1">Cybersecurity Supply Chain Risk Management</a> <small id="related-proj-acronym-1">C-SCRM</small></strong><br/> <span id="related-proj-overview-1">NEW! Request for Information | Evaluating and Improving NIST Cybersecurity Resources: The NIST...</span> </div> <div class="related-list-item" id="related-proj-2"> <strong><a href="/Projects/forum" id="related-proj-name-2">Federal Cybersecurity and Privacy Professionals Forum</a> <small id="related-proj-acronym-2"></small></strong><br/> <span id="related-proj-overview-2">The Federal Cybersecurity and Privacy Professionals Forum is an informal group sponsored by the...</span> </div> <div class="related-list-item" id="related-proj-3"> <strong><a href="/Projects/macos-security" id="related-proj-name-3">macOS Security</a> <small id="related-proj-acronym-3">APPLE-OS</small></strong><br/> <span id="related-proj-overview-3">NIST has traditionally published secure configuration guides for Apple operating systems, e.g., NIST...</span> </div> <div class="related-list-item" id="related-proj-4"> <strong><a href="/Projects/mcspwg" id="related-proj-name-4">Multi-Cloud Security Public Working Group</a> <small id="related-proj-acronym-4">MCSPWG</small></strong><br/> <span id="related-proj-overview-4">Cloud computing has become the core accelerator of the US Government's digital business...</span> </div> <p><strong> <a href="/projects?sortBy-lg=Name+ASC&ipp-lg=25&topics-lg=27490%7csystems+security+engineering&topicsMatch-lg=ANY" id="related-proj-all-link">View All Projects</a> </strong></p> </div> <div class="event-list" id="related-event-list"> <h3><i class="fa fa-calendar-o"></i> Related Events</h3> <div class="event-list-item" id="related-event-0"> <strong><a href="/Events/2020/de-mystifying-secure-software-development" id="related-event-link-0">De-mystifying Secure Software Development Webinar</a></strong><br /> <small><strong> <span id="related-event-start-date-0">June 23, 2020</span> </strong></small><br/> <span id="related-event-desc-0">Once seen as only tangential to cybersecurity planning, software security has recently emerged as a...</span> </div> <div class="event-list-item" id="related-event-1"> <strong><a href="/Events/2019/federal-computer-security-managers-forum-meeting" id="related-event-link-1">Federal Computer Security Managers Forum Meeting - February 28, 2019</a></strong><br /> <small><strong> <span id="related-event-start-date-1">February 28, 2019</span> </strong></small><br/> <span id="related-event-desc-1">Presentations & Speakers at a Glance: Overview of the Useable Security Program, Mary Theofanos...</span> </div> <div class="event-list-item" id="related-event-2"> <strong><a href="/Events/2016/Exploring-the-Dimensions-of-Trustworthiness-Chall" id="related-event-link-2">Exploring the Dimensions of Trustworthiness: Challenges and Opportunities</a></strong><br /> <small><strong> <span id="related-event-start-date-2">August 30, 2016</span> to <span id="related-event-end-date-2">August 31, 2016</span> </strong></small><br/> <span id="related-event-desc-2">Trustworthiness is a critical concern stakeholders have about Cyber-Physical Systems (CPS) and the...</span> </div> <p><strong> <a href="/events?sortBy-lg=StartDateTime+DESC&ipp-lg=25&topics-lg=27490%7csystems+security+engineering&topicsMatch-lg=ANY" id="related-event-all-link">View All Events</a> </strong></p> </div> <div class="news-list" id="related-news-list"> <h3><i class="fa fa-newspaper-o"></i> Related News</h3> <div class="news-list-item" id="related-news-item-0"> <strong><a href="/News/2024/nist-releases-cswp-31" id="related-news-link-0">NIST Releases CSWP 31</a></strong><br /> <small><strong id="related-news-date-0">September 26, 2024</strong></small><br/> <span id="related-news-desc-0">NIST Cybersecurity White Paper (CSWP) 31, Proxy Validation and Verification for Critical AI Systems:...</span> </div> <div class="news-list-item" id="related-news-item-1"> <strong><a href="/News/2022/guidance-on-engineering-trustworthy-secure-systems" id="related-news-link-1">NIST Releases Revised Guidance on Engineering Trustworthy Secure Systems</a></strong><br /> <small><strong id="related-news-date-1">November 16, 2022</strong></small><br/> <span id="related-news-desc-1">NIST has released a major revision to Special Publication (SP) 800-160 Volume 1, Engineering...</span> </div> <div class="news-list-item" id="related-news-item-2"> <strong><a href="/News/2022/engineering-trustworthy-secure-systems-final-draft" id="related-news-link-2">NIST Releases Final Public Draft: Engineering Trustworthy Secure Systems</a></strong><br /> <small><strong id="related-news-date-2">June 7, 2022</strong></small><br/> <span id="related-news-desc-2">NIST is releasing the final public draft of a major revision to Special Publication (SP) 800-160...</span> </div> <div class="news-list-item" id="related-news-item-3"> <strong><a href="/News/2022/draft-nist-sp-800-160-volume-1-revision-1-availabl" id="related-news-link-3">Draft NIST SP 800-160 Volume 1 Revision 1 Available for Comment</a></strong><br /> <small><strong id="related-news-date-3">January 11, 2022</strong></small><br/> <span id="related-news-desc-3">NIST is releasing the draft of a major revision to Special Publication (SP) 800-160 Volume 1,...</span> </div> <div class="news-list-item" id="related-news-item-4"> <strong><a href="/News/2021/revised-guidance-for-developing-cyber-resiliency" id="related-news-link-4">NIST Revises Guidance for Developing Cyber-Resilient Systems</a></strong><br /> <small><strong id="related-news-date-4">December 9, 2021</strong></small><br/> <span id="related-news-desc-4">NIST announces the release of a major update to Special Publication (SP) 800-160 Volume 2, Revision...</span> </div> <p><strong> <a href="/news?sortBy-lg=NewsDateTime+DESC&ipp-lg=25&topics-lg=27490%7csystems+security+engineering&topicsMatch-lg=ANY" id="related-news-all-link">View All News</a> </strong></p> </div> <div class="topics-related-list" id="related-pubs-list"> <h3><i class="fa fa-file-text-o"></i> Related Publications</h3> <div class="related-list-item" id="related-pubs-item-0"> <strong><a href="/pubs/cswp/31/proxy-validation-and-verification-for-cais/final" id="related-pubs-link-0">Proxy Validation and Verification for CAIS</a></strong><br/> <strong><small id="related-pubs-title-0">CSWP 31</small></strong><br/> <strong><small id="related-pubs-date-0" data-date-type="citation">September 26, 2024</small></strong><br/> <span id="related-pubs-status-0">Final</span> </div> <div class="related-list-item" id="related-pubs-item-1"> <strong><a href="/pubs/sp/1800/22/final" id="related-pubs-link-1">Mobile Device Security: Bring Your Own Device (BYOD)</a></strong><br/> <strong><small id="related-pubs-title-1">SP 1800-22</small></strong><br/> <strong><small id="related-pubs-date-1" data-date-type="citation">September 2023</small></strong><br/> <span id="related-pubs-status-1">Final</span> </div> <div class="related-list-item" id="related-pubs-item-2"> <strong><a href="/pubs/sp/1800/22/2pd" id="related-pubs-link-2">Mobile Device Security: BYOD</a></strong><br/> <strong><small id="related-pubs-title-2">SP 1800-22 (2nd Public Draft)</small></strong><br/> <strong><small id="related-pubs-date-2" data-date-type="citation">November 29, 2022</small></strong><br/> <span id="related-pubs-status-2">Withdrawn</span> </div> <div class="related-list-item" id="related-pubs-item-3"> <strong><a href="/pubs/sp/800/160/v1/r1/final" id="related-pubs-link-3">Engineering Trustworthy Secure Systems</a></strong><br/> <strong><small id="related-pubs-title-3">SP 800-160 Vol. 1 Rev. 1</small></strong><br/> <strong><small id="related-pubs-date-3" data-date-type="citation">November 2022</small></strong><br/> <span id="related-pubs-status-3">Final</span> </div> <div class="related-list-item" id="related-pubs-item-4"> <strong><a href="/pubs/sp/800/160/v1/r1/fpd" id="related-pubs-link-4">Engineering Trustworthy Secure Systems</a></strong><br/> <strong><small id="related-pubs-title-4">SP 800-160 Vol. 1 Rev. 1 (Final Public Draft)</small></strong><br/> <strong><small id="related-pubs-date-4" data-date-type="citation">June 7, 2022</small></strong><br/> <span id="related-pubs-status-4">Withdrawn</span> </div> <p><strong> <a href="/publications/search?sortBy-lg=relevance&viewMode-lg=brief&ipp-lg=25&status-lg=Draft%2CFinal&topics-lg=27490%7csystems+security+engineering&topicsMatch-lg=ANY&controlsMatch-lg=ANY" id="related-pubs-all-link">View All Publications</a> </strong></p> </div> <div class="topics-related-list" id="related-pres-list"> <h3><i class="fa fa-desktop"></i> Related Presentations</h3> <div class="related-list-item" id="presentation-container-0"> <strong><a href="/Presentations/2024/protecting-cyber-physical-space-systems" id="presentation-link-0">Protecting Cyber-Physical Space Systems: The SunRISE Engineering-Based Security Pilot Project</a></strong><br/> <strong><small> <span><span id="presentation-type-0">Presentation</span> - </span> <span id="presentation-date-0">September 11, 2024</span> </small></strong> </div> <div class="related-list-item" id="presentation-container-1"> <strong><a href="/Presentations/2024/protecting-cyber-physical-systems-and-technologies" id="presentation-link-1">Protecting Cyber-Physical Systems and Technologies</a></strong><br/> <strong><small> <span><span id="presentation-type-1">Presentation</span> - </span> <span id="presentation-date-1">July 18, 2024</span> </small></strong> </div> <div class="related-list-item" id="presentation-container-2"> <strong><a href="/Presentations/2023/mitres-system-of-trust-framework-and-community" id="presentation-link-2">MITRE’s System of Trust – Framework and Community</a></strong><br/> <strong><small> <span><span id="presentation-type-2">Presentation</span> - </span> <span id="presentation-date-2">June 1, 2023</span> </small></strong> </div> <div class="related-list-item" id="presentation-container-3"> <strong><a href="/Presentations/2022/transitioning-to-engineering-based-cybersecurity" id="presentation-link-3">Transitioning to Engineering-based Cybersecurity: SP 800-160 and Applying Design Principles to Develop Trustworthy Secure Systems</a></strong><br/> <strong><small> <span><span id="presentation-type-3">Presentation</span> - </span> <span id="presentation-date-3">January 27, 2022</span> </small></strong> </div> <div class="related-list-item" id="presentation-container-4"> <strong><a href="/Presentations/2021/defending-enterprise-systems-from-the-inside-out" id="presentation-link-4">Defending Enterprise Systems from the Inside Out: A Multidimensional Cyber Protection Strategy for the 21st Century</a></strong><br/> <strong><small> <span><span id="presentation-type-4">Presentation</span> - </span> <span id="presentation-date-4">April 23, 2021</span> </small></strong> </div> <p><strong> <a href="/search?ipp=25&sortBy=relevance&showOnly=presentations&topicsMatch=ANY&topics=27490%7csystems+security+engineering" id="related-pers-all-link">View All Presentations</a> </strong></p> </div> </div> <div class="col-md-4 col-sm-12"> <div class="bs-callout bs-callout-danger hidden-sm hidden-xs hidden-xxs" id="used-for-callout"> <h4>Used For</h4> <span id="used-for-content">SDLC; system development life cycle</span> </div> <div class="bs-callout bs-callout-warning topics-tree" id="topics-callout"> <h4>Topics</h4> <div class="category-topics-container" id="tcd-category-topics-container"><ul><li><i class="fa fa-minus fa-fw fa-sm" id="topics-expander-tcd-24663-24670" data-expander-for="/Topics/Security-and-Privacy/systems-security-engineering" data-expanded="true"></i> <strong><a data-topic-id="24670" data-topic-text="Security and Privacy" href="/Topics/Security-and-Privacy">Security and Privacy</a></strong><ul><li><i class="fa fa-plus fa-fw fa-sm" id="topics-expander-tcd-24670-27481"></i> <a data-topic-id="27481" data-topic-text="cryptography" href="/Topics/Security-and-Privacy/cryptography">cryptography</a><ul style="display: none;"><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27647" data-topic-text="digital signatures" href="/Topics/Security-and-Privacy/cryptography/digital-signatures">digital signatures</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27648" data-topic-text="encryption" href="/Topics/Security-and-Privacy/cryptography/encryption">encryption</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27649" data-topic-text="key management" href="/Topics/Security-and-Privacy/cryptography/key-management">key management</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="30027" data-topic-text="lightweight cryptography" href="/Topics/Security-and-Privacy/cryptography/lightweight-cryptography">lightweight cryptography</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27650" data-topic-text="message authentication" href="/Topics/Security-and-Privacy/cryptography/message-authentication">message authentication</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27651" data-topic-text="post-quantum cryptography" href="/Topics/Security-and-Privacy/cryptography/post-quantum-cryptography">post-quantum cryptography</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27652" data-topic-text="random number generation" href="/Topics/Security-and-Privacy/cryptography/random-number-generation">random number generation</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27653" data-topic-text="secure hashing" href="/Topics/Security-and-Privacy/cryptography/secure-hashing">secure hashing</a></li></ul> </li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27482" data-topic-text="cybersecurity supply chain risk management" href="/Topics/Security-and-Privacy/cyber-supply-chain-risk-management">cybersecurity supply chain risk management</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27483" data-topic-text="general security & privacy" href="/Topics/Security-and-Privacy/general-security-and-privacy">general security & privacy</a></li><li><i class="fa fa-plus fa-fw fa-sm" id="topics-expander-tcd-24670-27484"></i> <a data-topic-id="27484" data-topic-text="identity & access management" href="/Topics/Security-and-Privacy/identity-and-access-management">identity & access management</a><ul style="display: none;"><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27663" data-topic-text="access authorization" href="/Topics/Security-and-Privacy/identity-and-access-management/access-authorization">access authorization</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27664" data-topic-text="access control" href="/Topics/Security-and-Privacy/identity-and-access-management/access-control">access control</a></li><li><i class="fa fa-plus fa-fw fa-sm" id="topics-expander-tcd-27484-27665"></i> <a data-topic-id="27665" data-topic-text="authentication" href="/Topics/Security-and-Privacy/identity-and-access-management/authentication">authentication</a><ul style="display: none;"><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="36230" data-topic-text="passwords" href="/Topics/Security-and-Privacy/identity-and-access-management/authentication/passwords">passwords</a></li></ul> </li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27666" data-topic-text="Personal Identity Verification" href="/Topics/Security-and-Privacy/identity-and-access-management/PIV">Personal Identity Verification</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27667" data-topic-text="public key infrastructure" href="/Topics/Security-and-Privacy/identity-and-access-management/PKI">public key infrastructure</a></li></ul> </li><li><i class="fa fa-plus fa-fw fa-sm" id="topics-expander-tcd-24670-27485"></i> <a data-topic-id="27485" data-topic-text="privacy" href="/Topics/Security-and-Privacy/privacy">privacy</a><ul style="display: none;"><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27680" data-topic-text="personally identifiable information" href="/Topics/Security-and-Privacy/privacy/personally-identifiable-information">personally identifiable information</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27681" data-topic-text="privacy engineering" href="/Topics/Security-and-Privacy/privacy/privacy-engineering">privacy engineering</a></li></ul> </li><li><i class="fa fa-plus fa-fw fa-sm" id="topics-expander-tcd-24670-27486"></i> <a data-topic-id="27486" data-topic-text="risk management" href="/Topics/Security-and-Privacy/risk-management">risk management</a><ul style="display: none;"><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27682" data-topic-text="categorization" href="/Topics/Security-and-Privacy/risk-management/categorization">categorization</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27683" data-topic-text="continuous monitoring" href="/Topics/Security-and-Privacy/risk-management/continuous-monitoring">continuous monitoring</a></li><li><i class="fa fa-plus fa-fw fa-sm" id="topics-expander-tcd-27486-27684"></i> <a data-topic-id="27684" data-topic-text="controls" href="/Topics/Security-and-Privacy/risk-management/controls">controls</a><ul style="display: none;"><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27767" data-topic-text="controls assessment" href="/Topics/Security-and-Privacy/risk-management/controls/controls-assessment">controls assessment</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27768" data-topic-text="privacy controls" href="/Topics/Security-and-Privacy/risk-management/controls/privacy-controls">privacy controls</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27769" data-topic-text="security controls" href="/Topics/Security-and-Privacy/risk-management/controls/security-controls">security controls</a></li></ul> </li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27685" data-topic-text="risk assessment" href="/Topics/Security-and-Privacy/risk-management/risk-assessment">risk assessment</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27686" data-topic-text="roots of trust" href="/Topics/Security-and-Privacy/risk-management/roots-of-trust">roots of trust</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27687" data-topic-text="system authorization" href="/Topics/Security-and-Privacy/risk-management/system-authorization">system authorization</a></li><li><i class="fa fa-plus fa-fw fa-sm" id="topics-expander-tcd-27486-27688"></i> <a data-topic-id="27688" data-topic-text="threats" href="/Topics/Security-and-Privacy/risk-management/threats">threats</a><ul style="display: none;"><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27770" data-topic-text="advanced persistent threats" href="/Topics/Security-and-Privacy/risk-management/threats/advanced-persistent-threats">advanced persistent threats</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27771" data-topic-text="botnets" href="/Topics/Security-and-Privacy/risk-management/threats/botnets">botnets</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27772" data-topic-text="information sharing" href="/Topics/Security-and-Privacy/risk-management/threats/information-sharing">information sharing</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27773" data-topic-text="intrusion detection & prevention" href="/Topics/Security-and-Privacy/risk-management/threats/intrusion-detection-and-prevention">intrusion detection & prevention</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27774" data-topic-text="malware" href="/Topics/Security-and-Privacy/risk-management/threats/malware">malware</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="36185" data-topic-text="phishing" href="/Topics/Security-and-Privacy/risk-management/threats/phishing">phishing</a></li></ul> </li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27689" data-topic-text="vulnerability management" href="/Topics/Security-and-Privacy/risk-management/vulnerability-management">vulnerability management</a></li></ul> </li><li><i class="fa fa-plus fa-fw fa-sm" id="topics-expander-tcd-24670-27487"></i> <a data-topic-id="27487" data-topic-text="security & behavior" href="/Topics/Security-and-Privacy/security-and-behavior">security & behavior</a><ul style="display: none;"><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27709" data-topic-text="accessibility" href="/Topics/Security-and-Privacy/security-and-behavior/accessibility">accessibility</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27710" data-topic-text="behavior" href="/Topics/Security-and-Privacy/security-and-behavior/behavior">behavior</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27711" data-topic-text="usability" href="/Topics/Security-and-Privacy/security-and-behavior/usability">usability</a></li></ul> </li><li><i class="fa fa-plus fa-fw fa-sm" id="topics-expander-tcd-24670-27488"></i> <a data-topic-id="27488" data-topic-text="security measurement" href="/Topics/Security-and-Privacy/security-measurement">security measurement</a><ul style="display: none;"><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27690" data-topic-text="analytics" href="/Topics/Security-and-Privacy/security-measurement/analytics">analytics</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27691" data-topic-text="assurance" href="/Topics/Security-and-Privacy/security-measurement/assurance">assurance</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27692" data-topic-text="modeling" href="/Topics/Security-and-Privacy/security-measurement/modeling">modeling</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27693" data-topic-text="testing & validation" href="/Topics/Security-and-Privacy/security-measurement/testing-and-validation">testing & validation</a></li></ul> </li><li><i class="fa fa-plus fa-fw fa-sm" id="topics-expander-tcd-24670-27489"></i> <a data-topic-id="27489" data-topic-text="security programs & operations" href="/Topics/Security-and-Privacy/security-programs-and-operations">security programs & operations</a><ul style="display: none;"><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27694" data-topic-text="acquisition" href="/Topics/Security-and-Privacy/security-programs-and-operations/acquisition">acquisition</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27695" data-topic-text="asset management" href="/Topics/Security-and-Privacy/security-programs-and-operations/asset-management">asset management</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27696" data-topic-text="audit & accountability" href="/Topics/Security-and-Privacy/security-programs-and-operations/audit-and-accountability">audit & accountability</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27697" data-topic-text="awareness training & education" href="/Topics/Security-and-Privacy/security-programs-and-operations/awareness-training-education">awareness training & education</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27698" data-topic-text="configuration management" href="/Topics/Security-and-Privacy/security-programs-and-operations/configuration-management">configuration management</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27699" data-topic-text="contingency planning" href="/Topics/Security-and-Privacy/security-programs-and-operations/contingency-planning">contingency planning</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27700" data-topic-text="incident response" href="/Topics/Security-and-Privacy/security-programs-and-operations/incident-response">incident response</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27701" data-topic-text="maintenance" href="/Topics/Security-and-Privacy/security-programs-and-operations/maintenance">maintenance</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27702" data-topic-text="media protection" href="/Topics/Security-and-Privacy/security-programs-and-operations/media-protection">media protection</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27703" data-topic-text="patch management" href="/Topics/Security-and-Privacy/security-programs-and-operations/patch-management">patch management</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27704" data-topic-text="personnel security" href="/Topics/Security-and-Privacy/security-programs-and-operations/personnel-security">personnel security</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27705" data-topic-text="physical & environmental protection" href="/Topics/Security-and-Privacy/security-programs-and-operations/physical-and-environmental-protection">physical & environmental protection</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27706" data-topic-text="planning" href="/Topics/Security-and-Privacy/security-programs-and-operations/planning">planning</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27707" data-topic-text="program management" href="/Topics/Security-and-Privacy/security-programs-and-operations/program-management">program management</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27708" data-topic-text="security automation" href="/Topics/Security-and-Privacy/security-programs-and-operations/security-automation">security automation</a></li></ul> </li><li><i class="fa fa-minus fa-fw fa-sm" id="topics-expander-tcd-24670-27490" data-expander-for="/Topics/Security-and-Privacy/systems-security-engineering" data-expanded="true"></i> <span data-topic-id="27490" data-topic-text="systems security engineering">systems security engineering</span><ul><li><i class="fa fa-plus fa-fw fa-sm" id="topics-expander-tcd-27490-27713"></i> <a data-topic-id="27713" data-topic-text="trustworthiness" href="/Topics/Security-and-Privacy/systems-security-engineering/trustworthiness">trustworthiness</a><ul style="display: none;"><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27775" data-topic-text="reliability" href="/Topics/Security-and-Privacy/systems-security-engineering/trustworthiness/reliability">reliability</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27776" data-topic-text="resilience" href="/Topics/Security-and-Privacy/systems-security-engineering/trustworthiness/resilience">resilience</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27777" data-topic-text="safety" href="/Topics/Security-and-Privacy/systems-security-engineering/trustworthiness/safety">safety</a></li></ul> </li></ul> </li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="28469" data-topic-text="zero trust" href="/Topics/Security-and-Privacy/zero-trust">zero trust</a></li></ul> </li><li><i class="fa fa-plus fa-fw fa-sm" id="topics-expander-tcd-24663-24671"></i> <strong><a data-topic-id="24671" data-topic-text="Technologies" href="/Topics/technologies">Technologies</a></strong><ul style="display: none;"><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27491" data-topic-text="artificial intelligence" href="/Topics/technologies/artificial-intelligence">artificial intelligence</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27492" data-topic-text="big data" href="/Topics/technologies/big-data">big data</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27493" data-topic-text="biometrics" href="/Topics/technologies/biometrics">biometrics</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27494" data-topic-text="blockchain" href="/Topics/technologies/blockchain">blockchain</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27495" data-topic-text="cloud & virtualization" href="/Topics/technologies/cloud-computing-and-virtualization">cloud & virtualization</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27496" data-topic-text="combinatorial testing" href="/Topics/technologies/combinatorial-testing">combinatorial testing</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27497" data-topic-text="complexity" href="/Topics/technologies/complexity">complexity</a></li><li><i class="fa fa-plus fa-fw fa-sm" id="topics-expander-tcd-24671-27499"></i> <a data-topic-id="27499" data-topic-text="hardware" href="/Topics/technologies/hardware">hardware</a><ul style="display: none;"><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27714" data-topic-text="circuits" href="/Topics/technologies/hardware/circuits">circuits</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27715" data-topic-text="personal computers" href="/Topics/technologies/hardware/personal-computers">personal computers</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="36763" data-topic-text="semiconductors" href="/Topics/technologies/hardware/semiconductors">semiconductors</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27716" data-topic-text="sensors" href="/Topics/technologies/hardware/sensors">sensors</a></li></ul> </li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27498" data-topic-text="mobile" href="/Topics/technologies/mobile">mobile</a></li><li><i class="fa fa-plus fa-fw fa-sm" id="topics-expander-tcd-24671-27500"></i> <a data-topic-id="27500" data-topic-text="networks" href="/Topics/technologies/networks">networks</a><ul style="display: none;"><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27717" data-topic-text="email" href="/Topics/technologies/networks/email">email</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27718" data-topic-text="firewalls" href="/Topics/technologies/networks/firewalls">firewalls</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27719" data-topic-text="internet" href="/Topics/technologies/networks/internet">internet</a></li></ul> </li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27501" data-topic-text="quantum information science" href="/Topics/technologies/quantum-information-science">quantum information science</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27502" data-topic-text="servers" href="/Topics/technologies/servers">servers</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27503" data-topic-text="smart cards" href="/Topics/technologies/smart-cards">smart cards</a></li><li><i class="fa fa-plus fa-fw fa-sm" id="topics-expander-tcd-24671-27504"></i> <a data-topic-id="27504" data-topic-text="software & firmware" href="/Topics/technologies/software-firmware">software & firmware</a><ul style="display: none;"><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27720" data-topic-text="BIOS" href="/Topics/technologies/software-firmware/bios">BIOS</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27721" data-topic-text="databases" href="/Topics/technologies/software-firmware/databases">databases</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27722" data-topic-text="operating systems" href="/Topics/technologies/software-firmware/operating-systems">operating systems</a></li></ul> </li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27505" data-topic-text="storage" href="/Topics/technologies/storage">storage</a></li></ul> </li><li><i class="fa fa-plus fa-fw fa-sm" id="topics-expander-tcd-24663-24672"></i> <strong><a data-topic-id="24672" data-topic-text="Applications" href="/Topics/Applications">Applications</a></strong><ul style="display: none;"><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27456" data-topic-text="communications & wireless" href="/Topics/Applications/communications-and-wireless">communications & wireless</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27457" data-topic-text="cyber-physical systems" href="/Topics/Applications/cyber-physical-systems">cyber-physical systems</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27458" data-topic-text="cybersecurity education" href="/Topics/Applications/cybersecurity-education">cybersecurity education</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27459" data-topic-text="cybersecurity framework" href="/Topics/Applications/cybersecurity-framework">cybersecurity framework</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27460" data-topic-text="cybersecurity workforce" href="/Topics/Applications/cybersecurity-workforce">cybersecurity workforce</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27461" data-topic-text="enterprise" href="/Topics/Applications/enterprise">enterprise</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27462" data-topic-text="forensics" href="/Topics/Applications/forensics">forensics</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27463" data-topic-text="industrial control systems" href="/Topics/Applications/industrial-control-systems">industrial control systems</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27464" data-topic-text="Internet of Things" href="/Topics/Applications/Internet-of-Things">Internet of Things</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="29979" data-topic-text="mathematics" href="/Topics/Applications/mathematics">mathematics</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27920" data-topic-text="positioning navigation & timing" href="/Topics/Applications/positioning-navigation-timing">positioning navigation & timing</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27465" data-topic-text="small & medium business" href="/Topics/Applications/small-and-medium-business">small & medium business</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27466" data-topic-text="telework" href="/Topics/Applications/telework">telework</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27467" data-topic-text="voting" href="/Topics/Applications/voting">voting</a></li></ul> </li><li><i class="fa fa-plus fa-fw fa-sm" id="topics-expander-tcd-24663-24673"></i> <strong><a data-topic-id="24673" data-topic-text="Laws and Regulations" href="/Topics/Laws-and-Regulations">Laws and Regulations</a></strong><ul style="display: none;"><li><i class="fa fa-plus fa-fw fa-sm" id="topics-expander-tcd-24673-27468"></i> <a data-topic-id="27468" data-topic-text="executive documents" href="/Topics/Laws-and-Regulations/executive-documents">executive documents</a><ul style="display: none;"><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27668" data-topic-text="Comprehensive National Cybersecurity Initiative" href="/Topics/Laws-and-Regulations/executive-documents/CNCI">Comprehensive National Cybersecurity Initiative</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27669" data-topic-text="Cybersecurity Strategy and Implementation Plan" href="/Topics/Laws-and-Regulations/executive-documents/CSIP">Cybersecurity Strategy and Implementation Plan</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27670" data-topic-text="Cyberspace Policy Review" href="/Topics/Laws-and-Regulations/executive-documents/Cyberspace-Policy-Review">Cyberspace Policy Review</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27671" data-topic-text="Executive Order 13636" href="/Topics/Laws-and-Regulations/executive-documents/EO-13636">Executive Order 13636</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27672" data-topic-text="Executive Order 13702" href="/Topics/Laws-and-Regulations/executive-documents/EO-13702">Executive Order 13702</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27673" data-topic-text="Executive Order 13718" href="/Topics/Laws-and-Regulations/executive-documents/EO-13718">Executive Order 13718</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27674" data-topic-text="Executive Order 13800" href="/Topics/Laws-and-Regulations/executive-documents/EO-13800">Executive Order 13800</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27921" data-topic-text="Executive Order 13905" href="/Topics/Laws-and-Regulations/executive-documents/Executive-Order-13905">Executive Order 13905</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="28468" data-topic-text="Executive Order 14028" href="/Topics/Laws-and-Regulations/executive-documents/Executive-Order-14028">Executive Order 14028</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="36202" data-topic-text="Executive Order 14110" href="/Topics/Laws-and-Regulations/executive-documents/Executive-Order-14110">Executive Order 14110</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27675" data-topic-text="Federal Cybersecurity Research and Development Strategic Plan" href="/Topics/Laws-and-Regulations/executive-documents/Federal-Cybersecurity-Research-and-Development">Federal Cybersecurity Research and Development Strategic Plan</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27676" data-topic-text="Homeland Security Presidential Directive 7" href="/Topics/Laws-and-Regulations/executive-documents/HSPD-7">Homeland Security Presidential Directive 7</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27677" data-topic-text="Homeland Security Presidential Directive 12" href="/Topics/Laws-and-Regulations/executive-documents/HSPD-12">Homeland Security Presidential Directive 12</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27678" data-topic-text="OMB Circular A-11" href="/Topics/Laws-and-Regulations/executive-documents/OMB-A-11">OMB Circular A-11</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27679" data-topic-text="OMB Circular A-130" href="/Topics/Laws-and-Regulations/executive-documents/OMB-A-130">OMB Circular A-130</a></li></ul> </li><li><i class="fa fa-plus fa-fw fa-sm" id="topics-expander-tcd-24673-27469"></i> <a data-topic-id="27469" data-topic-text="laws" href="/Topics/Laws-and-Regulations/laws">laws</a><ul style="display: none;"><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="35985" data-topic-text="CHIPS and Science Act" href="/Topics/Laws-and-Regulations/laws/CHIPS-and-Science-Act">CHIPS and Science Act</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27654" data-topic-text="Cyber Security R&D Act" href="/Topics/Laws-and-Regulations/laws/Cyber-Security-Research-and-Development-Act">Cyber Security R&D Act</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27655" data-topic-text="Cybersecurity Enhancement Act" href="/Topics/Laws-and-Regulations/laws/Cybersecurity-Enhancement-Act">Cybersecurity Enhancement Act</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27656" data-topic-text="E-Government Act" href="/Topics/Laws-and-Regulations/laws/E-Gov-Act">E-Government Act</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27657" data-topic-text="Energy Independence and Security Act" href="/Topics/Laws-and-Regulations/laws/EISA">Energy Independence and Security Act</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27658" data-topic-text="Federal Information Security Modernization Act" href="/Topics/Laws-and-Regulations/laws/FISMA">Federal Information Security Modernization Act</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27659" data-topic-text="First Responder Network Authority" href="/Topics/Laws-and-Regulations/laws/FirstNet">First Responder Network Authority</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27660" data-topic-text="Health Insurance Portability and Accountability Act" href="/Topics/Laws-and-Regulations/laws/HIPAA">Health Insurance Portability and Accountability Act</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27661" data-topic-text="Help America Vote Act" href="/Topics/Laws-and-Regulations/laws/HAVA">Help America Vote Act</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="28580" data-topic-text="Internet of Things Cybersecurity Improvement Act" href="/Topics/Laws-and-Regulations/laws/Internet-of-Things-Cybersecurity-Improvement-Act">Internet of Things Cybersecurity Improvement Act</a></li></ul> </li><li><i class="fa fa-plus fa-fw fa-sm" id="topics-expander-tcd-24673-27470"></i> <a data-topic-id="27470" data-topic-text="regulations" href="/Topics/Laws-and-Regulations/regulations">regulations</a><ul style="display: none;"><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27662" data-topic-text="Federal Acquisition Regulation" href="/Topics/Laws-and-Regulations/regulations/FAR">Federal Acquisition Regulation</a></li></ul> </li></ul> </li><li><i class="fa fa-plus fa-fw fa-sm" id="topics-expander-tcd-24663-24674"></i> <strong><a data-topic-id="24674" data-topic-text="Activities and Products" href="/Topics/Activities-and-Products">Activities and Products</a></strong><ul style="display: none;"><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27452" data-topic-text="annual reports" href="/Topics/Activities-and-Products/annual-reports">annual reports</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27453" data-topic-text="conferences & workshops" href="/Topics/Activities-and-Products/conferences-and-workshops">conferences & workshops</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="30210" data-topic-text="groups" href="/Topics/Activities-and-Products/groups">groups</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="36366" data-topic-text="quick-start guides" href="/Topics/Activities-and-Products/quick-start-guides">quick-start guides</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27454" data-topic-text="reference materials" href="/Topics/Activities-and-Products/reference-materials">reference materials</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27455" data-topic-text="standards development" href="/Topics/Activities-and-Products/standards-development">standards development</a></li></ul> </li><li><i class="fa fa-plus fa-fw fa-sm" id="topics-expander-tcd-24663-24675"></i> <strong><a data-topic-id="24675" data-topic-text="Sectors" href="/Topics/Sectors">Sectors</a></strong><ul style="display: none;"><li><i class="fa fa-plus fa-fw fa-sm" id="topics-expander-tcd-24675-27472"></i> <a data-topic-id="27472" data-topic-text="energy" href="/Topics/Sectors/energy">energy</a><ul style="display: none;"><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27712" data-topic-text="smart grid" href="/Topics/Sectors/energy/smart-grid">smart grid</a></li></ul> </li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27473" data-topic-text="financial services" href="/Topics/Sectors/financial-services">financial services</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27474" data-topic-text="healthcare" href="/Topics/Sectors/healthcare">healthcare</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27475" data-topic-text="hospitality" href="/Topics/Sectors/hospitality">hospitality</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27476" data-topic-text="manufacturing" href="/Topics/Sectors/manufacturing">manufacturing</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27477" data-topic-text="public safety" href="/Topics/Sectors/public-safety">public safety</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27478" data-topic-text="retail" href="/Topics/Sectors/retail">retail</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27479" data-topic-text="telecommunications" href="/Topics/Sectors/telecommunications">telecommunications</a></li><li><i class="fa fa-fw fa-sm"></i> <a data-topic-id="27480" data-topic-text="transportation" href="/Topics/Sectors/transportation">transportation</a></li></ul> </li></ul></div> </div> <div class="bs-callout bs-callout-danger" id="categories-topics-callout"> <h4><i class="fa fa-tag"></i> Related Topics</h4> <p> <strong id="cat-0">Security and Privacy:</strong> <a href="/Topics/Security-and-Privacy/privacy/privacy-engineering" id="topic-0-0">privacy engineering</a> </p> </div> </div> </div> </div> <div class="row"> <div class="col-md-12 historical-data-area" id="historical-data-area"> <span>Created <span id="page-created-date">June 20, 2016</span>, Updated <span id="page-updated-date">June 22, 2020</span></span> </div> </div> <div id="footer-pusher"></div> </div> <footer id="footer"> <div class="container"> <div class="row"> <div class="col-sm-6"> <span class="hidden-xs"> <a href="https://www.nist.gov" title="National Institute of Standards and Technology" rel="home" target="_blank" class="footer-nist-logo" id="footer-nist-logo-link"> <img src="/CSRC/Media/images/nist-logo-brand-white.svg" alt="National Institute of Standards and Technology logo" id="footer-nist-logo" /> </a> </span> <div class="row footer-contact-container"> <div class="col-sm-12" id="footer-address"> <strong>HEADQUARTERS</strong><br> 100 Bureau Drive<br> Gaithersburg, MD 20899 </div> </div> </div> <div class="col-sm-6"> <ul class="social-list text-right" style="display: block;"> <li class="field-item service-twitter list-horiz"> <a href="https://twitter.com/NISTCyber" class="social-btn social-btn--large extlink ext" id="footer-social-twitter-link"> <i class="fa fa-twitter fa-fw"><span class="element-invisible">twitter</span></i><span class="ext"><span class="element-invisible"> (link is external)</span></span> </a> </li> <li class="field-item service-facebook list-horiz"> <a href="https://www.facebook.com/NIST" class="social-btn social-btn--large extlink ext" id="footer-social-facebook-link"> <i class="fa fa-facebook fa-fw"><span class="element-invisible">facebook</span></i><span class="ext"><span class="element-invisible"> (link is external)</span></span> </a> </li> <li class="field-item service-linkedin list-horiz"> <a href="https://www.linkedin.com/company/nist" class="social-btn social-btn--large extlink ext" id="footer-social-linkedin-link"> <i class="fa fa-linkedin fa-fw"><span class="element-invisible">linkedin</span></i><span class="ext"><span class="element-invisible"> (link is external)</span></span> </a> </li> <li class="field-item service-instagram list-horiz"> <a href="https://www.instagram.com/usnistgov/" class="social-btn social-btn--large extlink ext" id="footer-social-instagram-link"> <i class="fa fa-instagram fa-fw"><span class="element-invisible">instagram</span></i> <span class="ext"><span class="element-invisible"> (link is external)</span></span> </a> </li> <li class="field-item service-youtube list-horiz"> <a href="https://www.youtube.com/user/USNISTGOV" class="social-btn social-btn--large extlink ext" id="footer-social-youtube-link"> <i class="fa fa-youtube fa-fw"><span class="element-invisible">youtube</span></i><span class="ext"><span class="element-invisible"> (link is external)</span></span> </a> </li> <li class="field-item service-rss list-horiz"> <a href="https://www.nist.gov/news-events/nist-rss-feeds" class="social-btn social-btn--large extlink" id="footer-social-rss-link"> <i class="fa fa-rss fa-fw"><span class="element-invisible">rss</span></i> </a> </li> <li class="field-item service-govdelivery list-horiz last"> <a href="https://public.govdelivery.com/accounts/USNIST/subscriber/new?qsp=USNIST_3" class="social-btn social-btn--large extlink ext" title="Subscribe to CSRC and publication updates, and other NIST cybersecurity news" id="footer-social-govdelivery-link"> <i class="fa fa-envelope fa-fw"><span class="element-invisible">govdelivery</span></i><span class="ext"><span class="element-invisible"> (link is external)</span></span> </a> </li> </ul> <p class="text-right"> Want updates about CSRC and our publications? <a href="https://public.govdelivery.com/accounts/USNIST/subscriber/new?qsp=USNIST_3" class="btn btn-lg btn-primary" style="background-color: #12659c!important; border-color: #12659c!important;" id="footer-subscribe-link">Subscribe</a> </p> </div> </div> <div class="row hidden-sm hidden-md hidden-lg"> <div class="col-sm-12"> <a href="https://www.nist.gov" title="National Institute of Standards and Technology" rel="home" target="_blank" class="footer-nist-logo" id="footer-bottom-nist-logo-link"> <img src="/CSRC/Media/images/logo_rev.png" alt="National Institute of Standards and Technology logo" id="footer-bottom-nist-logo" /> </a> </div> </div> <div class="row"> <div class="col-sm-6"> <p> <a href="/about/contact" id="footer-contact-us-link">Contact Us</a> | <a href="https://www.nist.gov/about-nist/visit" style="display: inline-block;" id="footer-org-link">Our Other Offices</a> </p> </div> <div class="col-sm-6"> <span class="pull-right text-right"> Send inquiries to <a href="mailto:csrc-inquiry@nist.gov?subject=CSRC Inquiry" style="display: inline-block;" id="footer-inquiries-link">csrc-inquiry@nist.gov</a> </span> </div> </div> <div class="row"> <div class="footer-bottom-links-container" id="footer-bottom-links-container"> <ul> <li><a href="https://www.nist.gov/privacy-policy">Site Privacy</a></li> <li><a href="https://www.nist.gov/oism/accessibility">Accessibility</a></li> <li><a href="https://www.nist.gov/privacy">Privacy Program</a></li> <li><a href="https://www.nist.gov/oism/copyrights">Copyrights</a></li> <li><a href="https://www.commerce.gov/vulnerability-disclosure-policy">Vulnerability Disclosure</a></li> <li><a href="https://www.nist.gov/no-fear-act-policy">No Fear Act Policy</a></li> <li><a href="https://www.nist.gov/foia">FOIA</a></li> <li><a href="https://www.nist.gov/environmental-policy-statement">Environmental Policy</a></li> <li><a href="https://www.nist.gov/summary-report-scientific-integrity">Scientific Integrity</a></li> <li><a href="https://www.nist.gov/nist-information-quality-standards">Information Quality Standards</a></li> <li><a href="https://www.commerce.gov/">Commerce.gov</a></li> <li><a href="https://www.science.gov/">Science.gov</a></li> <li><a href="https://www.usa.gov/">USA.gov</a></li> <li><a href="https://vote.gov/">Vote.gov</a></li> </ul> </div> </div> </div> </footer> <script type="text/javascript" src="/dist/js/quick-collapse.js"></script> <script type="text/javascript" src="/dist/app.bundle.js"></script> <!-- USWDS Bottom --> <script type="text/javascript" src="/dist/uswds/js/uswds.min.js"></script> <script type="text/javascript" src="/dist/topics.bundle.js"></script> </body> </html>