Back to Frameworks

NIST SP 800-160

United States
vVol 1 Rev 1
11 domains
49 controls

Systems Security Engineering

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (11)

Agreement and Organisational Project Enabling Processes

1 controls
Controls in the Agreement and Organisational Project Enabling Processes domain of NIST SP 800-1601 controls
CodeTitle
SE-BCBusiness or Mission Analysis

Assurance

2 controls
Controls in the Assurance domain of NIST SP 800-1602 controls
CodeTitle
SE-ACAssurance Case Development
SE-IAInformation Assurance and Security Engineering Trade-offs

Cross-cutting

1 controls
Controls in the Cross-cutting domain of NIST SP 800-1601 controls
CodeTitle
SE-HFHuman Factors in Secure Systems Engineering

NIST SP 800-160: Access Control

5 controls

Logical and physical access controls (NIST SP 800-160)

Controls in the NIST SP 800-160: Access Control domain of NIST SP 800-1605 controls
CodeTitle
SP800-160-TM-CONFIGConfiguration Management Process
SP800-160-TM-DECISIONDecision Management Process
SP800-160-TM-INFOInformation Management Process
SP800-160-TM-MEASUREMeasurement Process
SP800-160-TM-RISKRisk Management Process

NIST SP 800-160: Asset Management

5 controls

Information asset management (NIST SP 800-160)

Controls in the NIST SP 800-160: Asset Management domain of NIST SP 800-1605 controls
CodeTitle
SP800-160-OPE-HRHuman Resource Management Process
SP800-160-OPE-KMKnowledge Management Process
SP800-160-OPE-QMQuality Management Process
SP800-160-TM-ASSESSProject Assessment and Control Process
SP800-160-TM-PLANProject Planning Process

NIST SP 800-160: Communications Security

3 controls

Network and communications security (NIST SP 800-160)

Controls in the NIST SP 800-160: Communications Security domain of NIST SP 800-1603 controls
CodeTitle
SP800-160-TE-DISPOSALDisposal Process
SP800-160-TE-MAINTAINMaintenance Process
SP800-160-TE-OPERATEOperation Process

NIST SP 800-160: Cryptography

5 controls

Cryptographic controls (NIST SP 800-160)

Controls in the NIST SP 800-160: Cryptography domain of NIST SP 800-1605 controls
CodeTitle
SP800-160-TE-ARCHArchitecture Definition Process
SP800-160-TE-DESIGNDesign Definition Process
SP800-160-TE-STAKEStakeholder Needs and Requirements Definition Process
SP800-160-TE-SYSREQSystem Requirements Definition Process
SP800-160-TM-QAQuality Assurance Process

NIST SP 800-160: Information Security Policies

5 controls

Organizational information security policies (NIST SP 800-160)

Controls in the NIST SP 800-160: Information Security Policies domain of NIST SP 800-1605 controls
CodeTitle
SP800-160-AGR-ACQAcquisition Process
SP800-160-AGR-SUPSupply Process
SP800-160-OPE-INFRAInfrastructure Management Process
SP800-160-OPE-LCMLife Cycle Model Management Process
SP800-160-OPE-PORTFOLIOPortfolio Management Process

NIST SP 800-160: Operations Security

6 controls

Secure operations and monitoring (NIST SP 800-160)

Controls in the NIST SP 800-160: Operations Security domain of NIST SP 800-1606 controls
CodeTitle
SP800-160-TE-ANALYSISSystem Analysis Process
SP800-160-TE-IMPLImplementation Process
SP800-160-TE-INTEGIntegration Process
SP800-160-TE-TRANSTransition Process
SP800-160-TE-VALIDATEValidation Process
SP800-160-TE-VERIFYVerification Process

Technical Management Processes

3 controls
Controls in the Technical Management Processes domain of NIST SP 800-1603 controls
CodeTitle
SE-CMConfiguration Management Process
SE-QAQuality Assurance Process
SE-RMRisk Management Process

Technical Processes

13 controls
Controls in the Technical Processes domain of NIST SP 800-16013 controls
CodeTitle
SE-ARCHArchitecture Definition
SE-DESDesign Definition
SE-DISDisposal
SE-IMPImplementation
SE-INTIntegration
SE-MNTMaintenance
SE-OPOperation
SE-SASystem Analysis
SE-SNStakeholder Needs and Requirements Definition
SE-SRSystem Requirements Definition
SE-TRTransition
SE-VALValidation
SE-VERVerification

Maps to 1 other framework

49 total controls
NIST SP 800-53 Rev 5
29 source controls mapped|16 target controls covered
59%

Frequently Asked Questions

What is NIST SP 800-160?

NIST SP 800-160 is a compliance framework from United States with 11 domains and 49 controls. Systems Security Engineering It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does NIST SP 800-160 have?

NIST SP 800-160 has 49 controls organised across 11 domains. The largest domains are Technical Processes (13 controls), NIST SP 800-160: Operations Security (6 controls), NIST SP 800-160: Access Control (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does NIST SP 800-160 map to?

NIST SP 800-160 maps to 1 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (59% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with NIST SP 800-160 compliance?

Start your NIST SP 800-160 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-160 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 49 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.

Get Started Free →

Free forever — no credit card required