United States

NIST SP 800-160

49 controls. 11 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

49 controls 11 frameworks share controls with it United States verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

NIST SP 800-160 Systems Security Engineering Evidence & Implementation Kit

49 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
SE-ACAssurance Case Development0
SE-ARCHArchitecture Definition0
SE-BCBusiness or Mission Analysis0
SE-CMConfiguration Management Process1
SE-DESDesign Definition0
SE-DISDisposal0
SE-HFHuman Factors in Secure Systems Engineering0
SE-IAInformation Assurance and Security Engineering Trade-offs0
SE-IMPImplementation3
SE-INTIntegration1
SE-MNTMaintenance0
SE-OPOperation0
SE-QAQuality Assurance Process0
SE-RMRisk Management Process0
SE-SASystem Analysis0
SE-SNStakeholder Needs and Requirements Definition0
SE-SRSystem Requirements Definition0
SE-TRTransition0
SE-VALValidation1
SE-VERVerification1
SP800-160-AGR-ACQAcquisition Process1
SP800-160-AGR-SUPSupply Process1
SP800-160-OPE-HRHuman Resource Management Process1
SP800-160-OPE-INFRAInfrastructure Management Process4
SP800-160-OPE-KMKnowledge Management Process1
SP800-160-OPE-LCMLife Cycle Model Management Process1
SP800-160-OPE-PORTFOLIOPortfolio Management Process1
SP800-160-OPE-QMQuality Management Process1
SP800-160-TE-ANALYSISSystem Analysis Process1
SP800-160-TE-ARCHArchitecture Definition Process1
SP800-160-TE-DESIGNDesign Definition Process1
SP800-160-TE-DISPOSALDisposal Process1
SP800-160-TE-IMPLImplementation Process3
SP800-160-TE-INTEGIntegration Process1
SP800-160-TE-MAINTAINMaintenance Process1
SP800-160-TE-OPERATEOperation Process1
SP800-160-TE-STAKEStakeholder Needs and Requirements Definition Process1
SP800-160-TE-SYSREQSystem Requirements Definition Process1
SP800-160-TE-TRANSTransition Process1
SP800-160-TE-VALIDATEValidation Process1
SP800-160-TE-VERIFYVerification Process2
SP800-160-TM-ASSESSProject Assessment and Control Process1
SP800-160-TM-CONFIGConfiguration Management Process2
SP800-160-TM-DECISIONDecision Management Process1
SP800-160-TM-INFOInformation Management Process1
SP800-160-TM-MEASUREMeasurement Process1
SP800-160-TM-PLANProject Planning Process1
SP800-160-TM-QAQuality Assurance Process1
SP800-160-TM-RISKRisk Management Process1

Tell me when NIST SP 800-160 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Audit reports
  • Risk-based audit plan
  • Findings tracker
  • Audit programme
  • Auditor competence records
  • audit plan
  • Policy referencing the control
  • Documented procedure
  • Evidence of operating effectiveness
  • Monitoring or review reports

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for NIST SP 800-160, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition