Deep Dive into SA-8
Let’s review one Control Family and then drill into its related part. Cloud providers should focus on the controls most likely to raise flags in the FAR/DFARS process. A control that has the potential to be overlooked and should not is the SA domain and in particular SA-8 Security and Privacy Engineering Principles. We know that the moderate baseline for FedRAMP and the scope of controls for NIST 171 Assessment haven't caught up with the IG's most recent monitoring mandate. Rather than suffer late in the acquisition process, cloud providers can use Cloud Control Management software (such as Security Compass SD Elements) to assign tasks that enable the evidence and readiness of their secure cloud product.
“SA” System and Services Acquisitions. Observe column headers in Green with the column referencing scoped Control ID and Control Enhancement ID assigned to the SP 800-53B FedRamp Assessment based according to their Baselines for Low Impact, Medium Impact, or High Impact, and for Privacy.
Figure: CSRC Control Family System and Services Acquisition
The CSRC online record SA-8 Security and Privacy Engineering Principles appear as assigned to all Baselines but only one of the thirty-three enhancements associated with evidence collected for the Privacy Baseline, SA-8(33). To conclude these tasks are not necessary would likely lead to issues down the line when attempting to defend the maturity of a cloud product. Building these tasks into a "Shift Left" approach would avoid future problems when asked to defend meeting the new EO 14028 requirements.
SA-8 is part of the SaaS development lifecycle and includes the stages specification, design, development, implementation, and modification. One can imagine the difficulty in deciding when and how to tag Cloud Product lifecycle tasks. Many of these enhancements are met through the enforcement of engineering rules such as those found in OWASP, [xxxiv] CIS Benchmarks, [xxxv] or MITRE ATT&CK®. [xxxvi] NIST controls use parameters [] as a convention to convey how they assign by “system”, “[Assignment: organization-defined systems security and privacy engineering principles]”. Each major System undergoes its own control review. Each system has its own SBOM, and each component of the system is part of an inventory. When DCMA (your Government Contract Administrator) requests further evidence of your SBOMB and all associated POA&M and SSP for your cloud offering, reporting such as that provided in SD Elements from Security Compass will most likely save you.
SBOM results in a configuration array, and evidence includes the use of specific SCAP rules enforced and measured according to their current threat models and baseline best practices.
|
Control (SA-8 Security and Privacy Engineering Principles) Apply the following systems security and privacy engineering principles in the specification, design, development, implementation, and modification of the system and system components: [Assignment: organization-defined systems security and privacy engineering principles]. Discussion Systems security and privacy engineering principles are closely related to and implemented throughout the system development life cycle (see SA-3). Organizations can apply systems security and privacy engineering principles to new systems under development or to systems undergoing upgrades. For existing systems, organizations apply systems security and privacy engineering principles to system upgrades and modifications to the extent feasible, given the current state of hardware, software, and firmware components within those systems. The application of systems security and privacy engineering principles helps organizations develop trustworthy, secure, and resilient systems and reduces the susceptibility to disruptions, hazards, threats, and the creation of privacy problems for individuals. Examples of system security engineering principles include: developing layered protections; establishing security and privacy policies, architecture, and controls as the foundation for design and development; incorporating security and privacy requirements into the system development life cycle; delineating physical and logical security boundaries; ensuring that developers are trained on how to build secure software; tailoring controls to meet organizational needs; and performing threat modeling to identify use cases, threat agents, attack vectors and patterns, design patterns, and compensating controls needed to mitigate risk. Organizations that apply systems security and privacy engineering concepts and principles can facilitate the development of trustworthy, secure systems, system components, and system services; reduce risk to acceptable levels; and make informed risk management decisions. System security engineering principles can also be used to protect against certain supply chain risks, including incorporating tamper-resistant hardware into a design. Related to: PL-8, PM-7, RA-2, RA-3, RA-9, SA-3, SA-4, SA-15, SA-17, SA-20, SC-, SC-3, SC-32, SC-39, SR-2, SR-3, SR-4, SR-5 (*) References:
|
SA-8 offers thirty-three (33) enhancements collectively contributing to the Engineering of a Secure and Private System. All Enhancements include their description and a discussion regarding their risk and implementation. Controls and Enhancements include the attribute “Related To:” which calls out the other parts of the framework representing the SIPOC (Suppliers, Inputs, Process, Outputs, Customers, Requirements) most often associated with this control outcome.
SA-8 Security and Privacy Engineering Principles - The Enhancements
| SA-8(1) Clear Abstractions SA-8(2) Least Common Mechanism SA-8(3) Modularity and Layering SA-8(4) Partially Ordered Dependencies SA-8(5) Efficiently Mediated Access SA-8(6) Minimized Sharing SA-8(7) Reduced Complexity SA-8(8) Secure Evolvability SA-8(9) Trusted Components SA-8(10) Hierarchical Trust SA-8(11) Inverse Modification Threshold |
SA-8(12) Hierarchical Protection |
SA-8(23) Secure Defaults SA-8(24) Secure Failure and Recovery SA-8(25) Economic Security SA-8(26) Performance Security SA-8(27) Human Factored Security SA-8(28) Acceptable Security SA-8(29) Repeatable and Documented Procedures SA-8(30) Procedural Rigor SA-8(31) Secure System Modification SA-8(32) Sufficient Documentation SA-8(33) Minimization* |
|
*The one FedRAMP Moderate Baseline Enhancement is: SECURITY AND PRIVACY ENGINEERING PRINCIPLES | MINIMIZATION Implement the privacy principle of minimization using [Assignment: organization-defined processes]. Discussion: The principle of minimization states that organizations should only process personally identifiable information that is directly relevant and necessary to accomplish an authorized purpose and should only maintain personally identifiable information for as long as is necessary to accomplish the purpose. Organizations have processes in place, consistent with applicable laws and policies, to implement the principle of minimization. |
||
Table 3 SA-8(3) Enhancement Description Discussion and Related Controls


Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics