Deep Dive into SA-8

Let’s review one Control Family and then drill into its related part. Cloud providers should focus on the controls most likely to raise flags in the FAR/DFARS process. A control that has the potential to be overlooked and should not is the SA domain and in particular SA-8 Security and Privacy Engineering Principles. We know that the moderate baseline for FedRAMP and the scope of controls for NIST 171 Assessment haven't caught up with the IG's most recent monitoring mandate. Rather than suffer late in the acquisition process, cloud providers can use Cloud Control Management software (such as Security Compass SD Elements) to assign tasks that enable the evidence and readiness of their secure cloud product.

“SA” System and Services Acquisitions. Observe column headers in Green with the column referencing scoped Control ID and Control Enhancement ID assigned to the SP 800-53B FedRamp Assessment based according to their Baselines for Low Impact, Medium Impact, or High Impact, and for Privacy.

System and Service Acquisition Family

Figure: CSRC Control Family System and Services Acquisition

The CSRC online record SA-8 Security and Privacy Engineering Principles appear as assigned to all Baselines but only one of the thirty-three enhancements associated with evidence collected for the Privacy Baseline, SA-8(33). To conclude these tasks are not necessary would likely lead to issues down the line when attempting to defend the maturity of a cloud product. Building these tasks into a "Shift Left" approach would avoid future problems when asked to defend meeting the new EO 14028 requirements. 

SA-8 is part of the SaaS development lifecycle and includes the stages specification, design, development, implementation, and modification. One can imagine the difficulty in deciding when and how to tag Cloud Product lifecycle tasks. Many of these enhancements are met through the enforcement of engineering rules such as those found in OWASP, [xxxiv] CIS Benchmarks, [xxxv] or MITRE ATT&CK®. [xxxvi]  NIST controls use parameters [] as a convention to convey how they assign by “system”, “[Assignment: organization-defined systems security and privacy engineering principles]”. Each major System undergoes its own control review. Each system has its own SBOM, and each component of the system is part of an inventory. When DCMA (your Government Contract Administrator) requests further evidence of your SBOMB and all associated POA&M and SSP for your cloud offering, reporting such as that provided in SD Elements from Security Compass will most likely save you.

SBOM results in a configuration array, and evidence includes the use of specific SCAP rules enforced and measured according to their current threat models and baseline best practices.

Control

(SA-8 Security and Privacy Engineering Principles)

Apply the following systems security and privacy engineering principles in the specification, design, development, implementation, and modification of the system and system components: [Assignment: organization-defined systems security and privacy engineering principles].

Discussion

Systems security and privacy engineering principles are closely related to and implemented throughout the system development life cycle (see SA-3). Organizations can apply systems security and privacy engineering principles to new systems under development or to systems undergoing upgrades. For existing systems, organizations apply systems security and privacy engineering principles to system upgrades and modifications to the extent feasible, given the current state of hardware, software, and firmware components within those systems.

The application of systems security and privacy engineering principles helps organizations develop trustworthy, secure, and resilient systems and reduces the susceptibility to disruptions, hazards, threats, and the creation of privacy problems for individuals. Examples of system security engineering principles include: developing layered protections; establishing security and privacy policies, architecture, and controls as the foundation for design and development; incorporating security and privacy requirements into the system development life cycle; delineating physical and logical security boundaries; ensuring that developers are trained on how to build secure software; tailoring controls to meet organizational needs; and performing threat modeling to identify use cases, threat agents, attack vectors and patterns, design patterns, and compensating controls needed to mitigate risk.

Organizations that apply systems security and privacy engineering concepts and principles can facilitate the development of trustworthy, secure systems, system components, and system services; reduce risk to acceptable levels; and make informed risk management decisions. System security engineering principles can also be used to protect against certain supply chain risks, including incorporating tamper-resistant hardware into a design. Related to: PL-8PM-7RA-2RA-3RA-9SA-3SA-4SA-15SA-17SA-20SC-SC-3SC-32SC-39SR-2SR-3SR-4SR-5 (*)

References:

SA-8 offers thirty-three (33) enhancements collectively contributing to the Engineering of a Secure and Private System. All Enhancements include their description and a discussion regarding their risk and implementation. Controls and Enhancements include the attribute “Related To:” which calls out the other parts of the framework representing the SIPOC (Suppliers, Inputs, Process, Outputs, Customers, Requirements) most often associated with this control outcome.

SA-8 Security and Privacy Engineering Principles - The Enhancements

SA-8(1) Clear Abstractions
SA-8(2) Least Common Mechanism
SA-8(3) Modularity and Layering
SA-8(4) Partially Ordered Dependencies
SA-8(5) Efficiently Mediated Access
SA-8(6) Minimized Sharing
SA-8(7) Reduced Complexity
SA-8(8) Secure Evolvability
SA-8(9) Trusted Components
SA-8(10) Hierarchical Trust
SA-8(11) Inverse Modification Threshold

SA-8(12) Hierarchical Protection
SA-8(13) Minimized Security Elements
SA-8(14) Least Privilege
SA-8(15) Predicate Permission
SA-8(16) Self-reliant Trustworthiness
SA-8(17) Secure Distributed Composition
SA-8(18) Trusted Communications Channels
SA-8(19) Continuous Protection
SA-8(20) Secure Metadata Management
SA-8(21) Self-analysis
SA-8(22) Accountability and Traceability

SA-8(23) Secure Defaults
SA-8(24) Secure Failure and Recovery
SA-8(25) Economic Security
SA-8(26) Performance Security
SA-8(27) Human Factored Security
SA-8(28) Acceptable Security
SA-8(29) Repeatable and Documented Procedures
SA-8(30) Procedural Rigor
SA-8(31) Secure System Modification
SA-8(32) Sufficient Documentation
SA-8(33) Minimization*

*The one FedRAMP Moderate Baseline Enhancement is: SECURITY AND PRIVACY ENGINEERING PRINCIPLES | MINIMIZATION

Implement the privacy principle of minimization using [Assignment: organization-defined processes].

Discussion: The principle of minimization states that organizations should only process personally identifiable information that is directly relevant and necessary to accomplish an authorized purpose and should only maintain personally identifiable information for as long as is necessary to accomplish the purpose. Organizations have processes in place, consistent with applicable laws and policies, to implement the principle of minimization.

Related to: PE-8PM-25SC-42SI-12

Table 3 SA-8(3) Enhancement Description Discussion and Related Controls

Main Menu