System security by design means engineering protection into a system from the beginning and carrying it through design, implementation, operation, and change—not relying on a final security test or asking users to repair weak defaults. NIST’s SP 800-160 Vol. 1 Rev. 1 provides a broad systems security engineering framework for doing that work.
What system security by design means
System security by design is an engineering discipline: identify what needs protection, translate those needs into security requirements, and use them to shape the system’s architecture, implementation, risk treatment, and assurance. Security is considered alongside the system’s purpose and operating conditions throughout its life cycle, rather than added as a late-stage feature.
As an Amazon Associate I earn from qualifying purchases.
The term “system” can encompass more than software. The approach applies to systems and systems-of-systems, including their components, people, physical elements, capabilities, and services. NIST says its systems security engineering principles and activities can be applied regardless of a system’s purpose, type, size, complexity, or life-cycle stage.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
The central reference is NIST SP 800-160 Vol. 1 Rev. 1, Engineering Trustworthy Secure Systems, published November 16, 2022. It sets out principles, concepts, activities, and tasks for engineering trustworthy secure systems; it is a framework to adapt to a system, not a universal control checklist.
#1 Best Overall
How security needs shape engineering work
A practical way to apply the discipline is to follow the relationship between stakeholder needs and engineering evidence. The activities below describe a useful flow; they should be adapted to the system rather than treated as a one-size-fits-all procedure.
1. Identify protection needs
Determine what stakeholders need protected, what harms or disruptions matter to the system’s mission, and the conditions in which it will operate. Consider the whole system boundary, including dependencies and people as well as technical components. These needs give security work a concrete purpose: protection is defined in relation to the system and its stakeholders, not as an abstract list of features.
Rank #2
2. Turn needs into security requirements
Translate protection needs into requirements that can guide engineering decisions and later be checked. Requirements should address relevant threats and risks, fit the system’s operating context, and be specific enough to inform design and verification. NIST SP 800-160 Vol. 1 Rev. 1 covers protection needs and requirements analysis as part of systems security engineering.
3. Shape architecture and design
Use those requirements to make architectural and design choices. Security should influence how system elements interact, where responsibilities sit, and how the system’s risks are treated. If a requirement cannot be met as planned, that gap should inform risk treatment and further design work rather than disappear from view.
Rank #3
4. Implement and assess the result
Build the selected protections into the system and assess whether the implementation meets its requirements. NIST’s framework includes security architecture and design, risk assessment and treatment, validation, and verification. These assurance activities provide evidence about whether the engineered system addresses its stated needs; a late test alone cannot substitute for decisions made throughout design and implementation.
5. Carry security through change and operation
Security remains relevant as a system is deployed, operated, maintained, and changed. New dependencies, changed conditions, or altered stakeholder needs can affect risk and the suitability of earlier design decisions. Applying the framework across life-cycle stages helps teams revisit requirements and treatment as the system evolves.
How the related approaches differ
“Systems security engineering,” “secure by design/default,” and “cyber resiliency” are complementary, not interchangeable labels. They answer different engineering questions.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →| Approach and reference | Primary audience and scope | Primary outcome | How to adapt it |
|---|---|---|---|
| Systems security engineering — NIST SP 800-160 Vol. 1 Rev. 1 | Systems engineering teams working across a system’s life cycle. | Trustworthy security built around stakeholder protection needs and security requirements. | Apply the principles and activities to the system’s purpose, type, size, complexity, and life-cycle stage. |
| Cyber resiliency — NIST SP 800-160 Vol. 2 Rev. 1 | Teams engineering systems to address cyber-related adversity. | The ability to anticipate, withstand, recover from, and adapt to cyber adversity. | Select and adapt resiliency constructs to technical and operational conditions and the threat environment. |
| Secure by design and secure by default — CISA and international partners’ joint guidance | Technology and software manufacturers responsible for product development and configuration. | Security integrated early and protective settings enabled by default, reducing the burden placed on customers. | Manufacturers should take ownership of security outcomes and support that commitment with transparency and accountability. |
What secure by default asks of manufacturers
Secure by design means integrating security into product development from the earliest phases. Secure by default means shipping products with important protective controls already enabled, rather than requiring customers to discover and configure them. The distinction matters: a product can be designed with security goals yet still transfer too much practical risk to users through its initial configuration.
Best Value
The joint guidance published by CISA, the FBI, NSA, and cybersecurity authorities from Australia, Canada, the United Kingdom, Germany, the Netherlands, and New Zealand on April 13, 2023, calls for manufacturers to take ownership of security outcomes, be transparent and accountable, and secure executive commitment. It frames the change as a shift in who bears the burden: manufacturers should not leave customers to compensate for avoidable product weaknesses.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Why cyber resiliency belongs in the design
Security engineering addresses protection needs and risk; cyber resiliency adds an explicit focus on how a system performs when cyber-related adversity occurs. NIST SP 800-160 Vol. 2 Rev. 1, Developing Cyber-Resilient Systems: A Systems Security Engineering Approach, describes the goal as enabling systems to anticipate, withstand, recover from, and adapt to cyber adversity.
Resiliency is not a substitute for preventing or reducing risk. It broadens design questions to include how the system can continue or restore important capabilities under adverse conditions and how it can adapt. The appropriate constructs depend on the system’s technical and operational setting and the threats it faces; NIST presents them as selectable and adaptable, not as a fixed recipe.
Which reference should you use?
- Use NIST SP 800-160 Vol. 1 Rev. 1 for the broad systems security engineering discipline and life-cycle framework.
- Use NIST SP 800-160 Vol. 2 Rev. 1 when the design question is specifically how to engineer cyber resiliency.
- Use CISA’s joint secure-by-design and -default guidance for manufacturer-facing product practices, default configuration, and accountability.
The references are complementary: a system team can use the broad engineering framework, incorporate resiliency objectives where appropriate, and apply manufacturer guidance to products and defaults within its scope. NIST SP 800-160 Vol. 1 Rev. 1 also says it can provide a basis for education and training programs, professional certifications, and assessment criteria.
Publication dates and revision context
NIST SP 800-160 Vol. 1 Rev. 1 was published November 16, 2022, superseding the March 2018 volume. NIST SP 800-160 Vol. 2 Rev. 1 was finalized December 9, 2021, superseding the November 2019 volume. The CISA-led joint guidance was announced April 13, 2023. These dates identify the cited publications; consult their official pages for current publication status and any subsequent updates or errata.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




