NIST SP 800-160
Systems Security Engineering
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (11)
Agreement and Organisational Project Enabling Processes
| Code | Title |
|---|---|
| SE-BC | Business or Mission Analysis |
Assurance
| Code | Title |
|---|---|
| SE-AC | Assurance Case Development |
| SE-IA | Information Assurance and Security Engineering Trade-offs |
Cross-cutting
| Code | Title |
|---|---|
| SE-HF | Human Factors in Secure Systems Engineering |
NIST SP 800-160: Access Control
Logical and physical access controls (NIST SP 800-160)
| Code | Title |
|---|---|
| SP800-160-TM-CONFIG | Configuration Management Process |
| SP800-160-TM-DECISION | Decision Management Process |
| SP800-160-TM-INFO | Information Management Process |
| SP800-160-TM-MEASURE | Measurement Process |
| SP800-160-TM-RISK | Risk Management Process |
NIST SP 800-160: Asset Management
Information asset management (NIST SP 800-160)
| Code | Title |
|---|---|
| SP800-160-OPE-HR | Human Resource Management Process |
| SP800-160-OPE-KM | Knowledge Management Process |
| SP800-160-OPE-QM | Quality Management Process |
| SP800-160-TM-ASSESS | Project Assessment and Control Process |
| SP800-160-TM-PLAN | Project Planning Process |
NIST SP 800-160: Communications Security
Network and communications security (NIST SP 800-160)
| Code | Title |
|---|---|
| SP800-160-TE-DISPOSAL | Disposal Process |
| SP800-160-TE-MAINTAIN | Maintenance Process |
| SP800-160-TE-OPERATE | Operation Process |
NIST SP 800-160: Cryptography
Cryptographic controls (NIST SP 800-160)
| Code | Title |
|---|---|
| SP800-160-TE-ARCH | Architecture Definition Process |
| SP800-160-TE-DESIGN | Design Definition Process |
| SP800-160-TE-STAKE | Stakeholder Needs and Requirements Definition Process |
| SP800-160-TE-SYSREQ | System Requirements Definition Process |
| SP800-160-TM-QA | Quality Assurance Process |
NIST SP 800-160: Information Security Policies
Organizational information security policies (NIST SP 800-160)
| Code | Title |
|---|---|
| SP800-160-AGR-ACQ | Acquisition Process |
| SP800-160-AGR-SUP | Supply Process |
| SP800-160-OPE-INFRA | Infrastructure Management Process |
| SP800-160-OPE-LCM | Life Cycle Model Management Process |
| SP800-160-OPE-PORTFOLIO | Portfolio Management Process |
NIST SP 800-160: Operations Security
Secure operations and monitoring (NIST SP 800-160)
| Code | Title |
|---|---|
| SP800-160-TE-ANALYSIS | System Analysis Process |
| SP800-160-TE-IMPL | Implementation Process |
| SP800-160-TE-INTEG | Integration Process |
| SP800-160-TE-TRANS | Transition Process |
| SP800-160-TE-VALIDATE | Validation Process |
| SP800-160-TE-VERIFY | Verification Process |
Technical Management Processes
| Code | Title |
|---|---|
| SE-CM | Configuration Management Process |
| SE-QA | Quality Assurance Process |
| SE-RM | Risk Management Process |
Technical Processes
| Code | Title |
|---|---|
| SE-ARCH | Architecture Definition |
| SE-DES | Design Definition |
| SE-DIS | Disposal |
| SE-IMP | Implementation |
| SE-INT | Integration |
| SE-MNT | Maintenance |
| SE-OP | Operation |
| SE-SA | System Analysis |
| SE-SN | Stakeholder Needs and Requirements Definition |
| SE-SR | System Requirements Definition |
| SE-TR | Transition |
| SE-VAL | Validation |
| SE-VER | Verification |
Maps to 1 other framework
Frequently Asked Questions
What is NIST SP 800-160?
NIST SP 800-160 is a compliance framework from United States with 11 domains and 49 controls. Systems Security Engineering It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does NIST SP 800-160 have?
NIST SP 800-160 has 49 controls organised across 11 domains. The largest domains are Technical Processes (13 controls), NIST SP 800-160: Operations Security (6 controls), NIST SP 800-160: Access Control (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does NIST SP 800-160 map to?
NIST SP 800-160 maps to 1 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (59% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with NIST SP 800-160 compliance?
Start your NIST SP 800-160 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-160 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 49 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.
Get Started Free →Free forever — no credit card required