NIST SP 800-160
NIST SP 800-160 is a multi-volume NIST publication that describes how to build security and resilience into systems from the ground up, treating security as an engineering discipline rather than something added on afterward. Volume 1 focuses on engineering trustworthy secure systems, while Volume 2 focuses on making systems cyber-resilient so they can withstand and recover from attacks. It is guidance intended to inform engineering practice, and readers should confirm the specific volume and revision that applies to their needs against the current official NIST text.
NIST SP 800-160 is a NIST Special Publication series, authored under Ron Ross and colleagues, that establishes principles, concepts, activities, and tasks for systems security engineering (SSE) as an element of the broader systems engineering process. Volume 1 addresses security from a stakeholder protection needs, concerns, and requirements perspective and applies established engineering methods to produce trustworthy secure systems; it was originally issued in November 2016, updated in March 2018 (Update 2), and a Revision 1 was released in 2022 under the title 'Engineering Trustworthy Secure Systems.' Volume 2 addresses cyber resiliency engineering as an emerging specialty discipline for developing cyber-resilient systems, with a Revision 1 finalized in 2021. As of the applicable revision, this publication is guidance that provides a basis for a discipline and set of practices rather than a mandatory control baseline; practitioners should not conflate it with control catalogs such as NIST SP 800-53 or CUI protection requirements in NIST SP 800-171, and should verify the current volume, revision, and update status against the authoritative NIST CSRC text.
Why it matters
NIST SP 800-160 addresses a persistent gap in security practice: the tendency to treat security as a feature bolted on after a system is already designed and built. By framing security as an engineering discipline that begins with stakeholder protection needs, concerns, and requirements, the publication provides a basis for building trustworthiness and resilience into systems from the outset rather than remediating weaknesses later. For organizations engineering complex systems, particularly those supporting defense and public sector missions, this shift can reduce the accumulation of design-level vulnerabilities that are far more costly to address once a system is fielded.
The series also matters because it distinguishes two related but separate concerns. Volume 1 concentrates on engineering trustworthy secure systems, while Volume 2 concentrates on cyber resiliency, the capacity of a system to anticipate, withstand, recover from, and adapt to adverse conditions and attacks. This distinction is important for practitioners who must plan not only to prevent compromise but to continue operating a mission through it. Cyber resiliency engineering is described in the guidance as an emerging specialty systems engineering discipline, which signals that expectations and practices in this area continue to evolve.
A common and consequential mistake is to treat SP 800-160 as a mandatory control baseline. As of the applicable revision, it is guidance that establishes principles, concepts, activities, and tasks for a discipline and set of practices, it is not a control catalog like NIST SP 800-53, nor does it define the CUI protection requirements found in NIST SP 800-171. Readers should not assume that applying SP 800-160 satisfies any specific compliance obligation, and should verify the current volume, revision, and update status against the authoritative NIST CSRC text before relying on it in an assessment or authorization context.
Who it's relevant to
Inside SP 800-160
Common questions
Answers to the questions practitioners most commonly ask about SP 800-160.