SA-08 Security Engineering Principles

System and Services Acquisition

Low Moderate High

Description

The organization designs and implements the information system using security engineering principles.\n

Supplemental Guidance

NIST Special Publication 800-27 provides guidance on engineering principles for information system security. The application of security engineering principles is primarily targeted at new development information systems or systems undergoing major upgrades and is integrated into the system development life cycle. For legacy information systems, the organization applies security engineering principles to system upgrades and modifications, to the extent feasible, given the current state of the hardware, software, and firmware components within the system.\n

Changes from Rev 4

Title changed from 'Security Engineering Principles' Control text adds privacy and system components New parameter requires specifying applicable systems security and privacy engineering principles Discussion expanded to explain benefits Incorporates withdrawn control SA-13

Enhancements

(0) None.\n

Compliance Mappings

ISO 27002:2022

8.128.258.268.278.38.58.9

COBIT 2019

APO03.01APO03.02APO03.03APO03.04APO03.05APO04.05BAI10.02DSS06.06

CIS Controls v8

10.310.410.512.212.61616.1016.74.14.104.24.34.44.54.64.74.8

NIST CSF 2.0

PR.DS-10PR.IRPR.IR-01PR.IR-03PR.PSPR.PS-05

SOC 2 TSC

CC2.2CC3.2CC5.1CC5.2CC6.1-POF2CC6.1-POF7CC6.7-POF1CC7.1CC7.1-POF1CC8.1CC8.1-POF12CC8.1-POF15CC8.1-POF18CC8.1-POF6

ISO 17799 (legacy)

12.1

COBIT 4.1 (legacy)

AI2.4