NIST Fellow Ron Ross wrote in a blog post published Tuesday the Special Publication 800-160 Systems Security Engineering guide was developed after four years of research and development.
“Our fundamental cybersecurity problem can be summed up in three wordsâtoo much complexity,” Ross wrote.
“There are simply too many basesâall the software, firmware, and hardware components that we rely on to run our critical infrastructure, business, and industrial systemsâfor us to cover as it is, and weâre adding to the number of bases all the time,” he added.
Ross noted increased complexity gives adversaries “limitless opportunity” to attack vulnerabilities in underlying systems.
Fundamental weaknesses in system architecture and design can be mitigated through a “holistic approach” based on systems security engineering techniques and design principles, according to Ross.
The security engineering approach is designed to help systems block penetration; limit damage from disruptions, hazards and threats; and continue to support missions and business operations after security incidents, Ross stated.
Organizations should integrate engineering-based security design principles at physical and virtual levels to address vulnerabilities, Ross said.