Skip to main content
Category: NIST Standards & Publications

NIST SP 800-160

Also known as: SP 800-160, NIST Special Publication 800-160, Systems Security Engineering (SP 800-160 Vol. 1), Engineering Trustworthy Secure Systems (SP 800-160 Vol. 1 Rev. 1), Developing Cyber-Resilient Systems (SP 800-160 Vol. 2)
Simply put

NIST SP 800-160 is a multi-volume NIST publication that describes how to build security and resilience into systems from the ground up, treating security as an engineering discipline rather than something added on afterward. Volume 1 focuses on engineering trustworthy secure systems, while Volume 2 focuses on making systems cyber-resilient so they can withstand and recover from attacks. It is guidance intended to inform engineering practice, and readers should confirm the specific volume and revision that applies to their needs against the current official NIST text.

Formal definition

NIST SP 800-160 is a NIST Special Publication series, authored under Ron Ross and colleagues, that establishes principles, concepts, activities, and tasks for systems security engineering (SSE) as an element of the broader systems engineering process. Volume 1 addresses security from a stakeholder protection needs, concerns, and requirements perspective and applies established engineering methods to produce trustworthy secure systems; it was originally issued in November 2016, updated in March 2018 (Update 2), and a Revision 1 was released in 2022 under the title 'Engineering Trustworthy Secure Systems.' Volume 2 addresses cyber resiliency engineering as an emerging specialty discipline for developing cyber-resilient systems, with a Revision 1 finalized in 2021. As of the applicable revision, this publication is guidance that provides a basis for a discipline and set of practices rather than a mandatory control baseline; practitioners should not conflate it with control catalogs such as NIST SP 800-53 or CUI protection requirements in NIST SP 800-171, and should verify the current volume, revision, and update status against the authoritative NIST CSRC text.

Why it matters

NIST SP 800-160 addresses a persistent gap in security practice: the tendency to treat security as a feature bolted on after a system is already designed and built. By framing security as an engineering discipline that begins with stakeholder protection needs, concerns, and requirements, the publication provides a basis for building trustworthiness and resilience into systems from the outset rather than remediating weaknesses later. For organizations engineering complex systems, particularly those supporting defense and public sector missions, this shift can reduce the accumulation of design-level vulnerabilities that are far more costly to address once a system is fielded.

The series also matters because it distinguishes two related but separate concerns. Volume 1 concentrates on engineering trustworthy secure systems, while Volume 2 concentrates on cyber resiliency, the capacity of a system to anticipate, withstand, recover from, and adapt to adverse conditions and attacks. This distinction is important for practitioners who must plan not only to prevent compromise but to continue operating a mission through it. Cyber resiliency engineering is described in the guidance as an emerging specialty systems engineering discipline, which signals that expectations and practices in this area continue to evolve.

A common and consequential mistake is to treat SP 800-160 as a mandatory control baseline. As of the applicable revision, it is guidance that establishes principles, concepts, activities, and tasks for a discipline and set of practices, it is not a control catalog like NIST SP 800-53, nor does it define the CUI protection requirements found in NIST SP 800-171. Readers should not assume that applying SP 800-160 satisfies any specific compliance obligation, and should verify the current volume, revision, and update status against the authoritative NIST CSRC text before relying on it in an assessment or authorization context.

Who it's relevant to

Systems and security engineers
Engineers designing and building complex systems can use SP 800-160 Volume 1 as a basis for integrating security into the systems engineering lifecycle from stakeholder requirements onward, rather than treating it as a post-design activity. They should treat the publication as guidance informing engineering practice and confirm the applicable volume and revision against the current NIST text.
Resilience and mission assurance planners
Those responsible for ensuring systems can withstand and recover from attacks can draw on SP 800-160 Volume 2, which addresses cyber resiliency engineering as an emerging specialty discipline. Because the field is described as evolving, planners should verify the current revision and treat practices as guidance rather than fixed requirements.
Program managers and acquisition officials
Personnel overseeing system development or procurement can reference SP 800-160 to inform how security engineering expectations are framed in a program. They should not treat the publication as a compliance control baseline or as a substitute for control catalogs such as NIST SP 800-53 or CUI requirements in NIST SP 800-171, and should confirm any contractual application against authoritative sources.
Compliance officers and assessors
Compliance and assessment professionals should understand that SP 800-160, as of the applicable revision, provides a basis for a discipline and set of practices rather than a mandatory set of controls. Distinguishing this engineering guidance from prescriptive control frameworks helps avoid conflating engineering practice with a defined authorization or compliance obligation.

Inside SP 800-160

Volume 1 (Systems Security Engineering foundations)
NIST SP 800-160, Volume 1 addresses systems security engineering considerations as applied within systems engineering processes. Volume 1 was originally published in November 2016 and later revised; practitioners should confirm the current revision and its publication date against the official NIST source, as the guidance has been updated since its initial 2016 release.
Volume 2 (Cyber resiliency)
A separate volume in the SP 800-160 series focused on developing cyber-resilient systems. Because the volumes address distinct topics, they should not be treated as interchangeable; readers should verify the specific volume and revision relevant to their needs against current NIST publications.
Engineering-based perspective
The publication frames security as an integral part of systems engineering rather than a bolt-on activity, emphasizing that security properties are engineered into systems throughout the life cycle. Specific process detail should be confirmed against the applicable revision.
Non-binding guidance
As a NIST Special Publication, SP 800-160 provides guidance and is generally advisory in nature unless made mandatory by a specific agency policy, contract, or other authority. Its status in any given environment should be verified against the governing requirement.

Common questions

Answers to the questions practitioners most commonly ask about SP 800-160.

Is NIST SP 800-160 a control catalog like NIST SP 800-53 that I can assess a system against for compliance?
No. NIST SP 800-160 is not a control catalog and should not be treated as interchangeable with NIST SP 800-53. NIST SP 800-53 provides a catalog of security and privacy controls used to build baselines for authorization, whereas NIST SP 800-160 provides engineering-focused guidance on building security into systems throughout the system life cycle. NIST SP 800-160 generally informs how you design and engineer a trustworthy system rather than serving as a checklist you assess against for a compliance determination. Confirm the applicable use of each publication against the current official NIST text and your agency's tailoring.
Does following NIST SP 800-160 satisfy my RMF or FISMA obligations, so that I don't also need NIST SP 800-37 or NIST SP 800-53?
No. NIST SP 800-160 does not replace the Risk Management Framework process described in NIST SP 800-37 or the control catalog in NIST SP 800-53. It complements them by addressing the systems security engineering perspective. Compliance and authorization activities under FISMA for civilian systems, and under the RMF for DoD systems, generally still rely on the established RMF steps and control baselines. Following systems security engineering guidance can support those efforts but does not by itself constitute an authorization or a compliance determination, and assessment is distinct from authorization. Verify how each publication applies within your agency's framework.
Which NIST SP 800-160 volume should I reference for engineering trustworthy secure systems versus for cyber resiliency?
NIST SP 800-160 is organized into multiple volumes with distinct focuses. Volume 1 addresses systems security engineering and the considerations for engineering trustworthy secure systems, while a separate volume addresses cyber resiliency considerations. Because the volumes serve different purposes and have been revised on different schedules, confirm the current title, revision, and scope of each volume against the official NIST publication before citing a specific one in your documentation.
At what point in a project should systems security engineering guidance from NIST SP 800-160 be applied?
The guidance is generally intended to be applied across the full system life cycle rather than only at a single phase. In most implementations, applying security engineering principles as early as concept and requirements definition, and continuing through design, development, and disposal, is more effective than attempting to retrofit security later. Because specific life cycle processes and terminology can vary by organization and by the underlying systems engineering standards referenced, confirm the applicable life cycle model and how the guidance maps to it for your program.
Is NIST SP 800-160 mandatory for federal contractors and agencies?
NIST Special Publications are generally guidance documents rather than self-executing mandates, and their binding status depends on how they are incorporated by an agency, a contract, or another authority. Whether NIST SP 800-160 applies to your effort typically depends on contractual requirements, agency policy, or program direction rather than the publication itself. Do not assume it is either mandatory or optional in the abstract; verify any applicability against your specific contract terms, agency policy, and current authoritative sources.
How does NIST SP 800-160 relate to the NIST SP 800-53 controls I still have to implement?
NIST SP 800-160 and NIST SP 800-53 serve complementary roles. NIST SP 800-160 provides the engineering perspective on how to design and build a system so that security is integrated by design, while NIST SP 800-53 provides the specific controls that are selected, tailored into baselines, and assessed. In practice, security engineering activities can inform which controls are needed and how they are realized, but you generally still implement, document, and assess controls through the established control catalog and RMF processes. Confirm the current revisions of both publications and your agency's tailoring before relying on this relationship.

Common misconceptions

SP 800-160 Volume 1 was first published in 2018.
Volume 1 was originally published in November 2016. It was subsequently updated (the March 2018 update is commonly referenced as Update 2), so the 2018 date reflects a revision rather than the first release. Confirm the current revision against the official NIST source.
SP 800-160 is a control catalog like other NIST publications and can substitute for a control baseline.
SP 800-160 provides systems security engineering guidance and is not itself a control catalog; it does not replace control-based publications. Its relationship to any control set should be verified against the applicable revision and agency tailoring.
Following SP 800-160 is mandatory for all systems.
As a NIST Special Publication, its guidance is generally advisory unless a specific policy, contract, or authority makes it mandatory. Readers should confirm whether it is required in their particular environment against the governing source.

Best practices

Verify which volume and revision of SP 800-160 applies to your work, since Volume 1 (systems security engineering) and Volume 2 (cyber resiliency) address distinct topics.
Confirm the current publication and update status directly against the official NIST source rather than relying on a single date, noting that Volume 1 originated in November 2016 and has been updated since.
Treat SP 800-160 as engineering guidance that integrates security into the systems engineering life cycle rather than as a standalone control baseline.
Determine whether the guidance is advisory or mandatory in your specific context by checking the governing policy, contract, or authority.
Do not conflate SP 800-160 with control-focused publications; verify how it relates to any applicable control set and agency tailoring against current authoritative text.