NIST 800-53 r5 · Controls catalogue · Family SA
SA-8Security and Privacy Engineering Principles
Apply the following systems security and privacy engineering principles in the specification, design, development, implementation, and modification of the system and system components: {{ insert: param, sa-8_prm_1 }}.
Last updated: 22 August 2026 14:14 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: partial · 2 mapping(s) from 1 framework(s): OWASP-Web 2 (partial)
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (20)
- T1005 Data from Local System Collection
- T1025 Data from Removable Media Collection
- T1041 Exfiltration Over C2 Channel Exfiltration
- T1048 Exfiltration Over Alternative Protocol Exfiltration
- T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol Exfiltration
- T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol Exfiltration
- T1052 Exfiltration Over Physical Medium Exfiltration
- T1052.001 Exfiltration over USB Exfiltration
- T1078 Valid Accounts Stealth, Persistence, Privilege Escalation, Initial Access
- T1078.001 Default Accounts Stealth, Persistence, Privilege Escalation, Initial Access
- T1078.003 Local Accounts Stealth, Persistence, Privilege Escalation, Initial Access
- T1078.004 Cloud Accounts Stealth, Persistence, Privilege Escalation, Initial Access
- T1134.005 SID-History Injection Stealth, Privilege Escalation
- T1190 Exploit Public-Facing Application Initial Access
- T1213.003 Code Repositories Collection
- T1482 Domain Trust Discovery Discovery
- T1559.003 XPC Services Execution
- T1567 Exfiltration Over Web Service Exfiltration
- T1574.001 DLL Stealth, Execution
- T1647 Plist File Modification Defense Impairment
Weaknesses this control addresses (9)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-284 | Improper Access Control | 6,900+ | Complete-mediation and least-privilege principles ensure proper access-control design and enforcement. |
CWE-269 | Improper Privilege Management | 3,400+ | Least-privilege and separation-of-duties principles prevent improper privilege management. |
CWE-306 | Missing Authentication for Critical Function | 3,300+ | Complete-mediation principle requires authentication for critical functions. |
CWE-732 | Incorrect Permission Assignment for Critical Resource | 1,900+ | Permission-assignment and least-privilege principles prevent incorrect critical-resource permissions. |
CWE-693 | Protection Mechanism Failure | 700+ | Engineering principles ensure protection mechanisms are correctly specified and implemented. |
CWE-250 | Execution with Unnecessary Privileges | 300+ | Least-privilege engineering principle directly reduces execution with unnecessary privileges. |
CWE-653 | Improper Isolation or Compartmentalization | 73 | Separation-of-privilege and least-common-mechanism principles enforce proper isolation. |
CWE-636 | Not Failing Securely ('Failing Open') | 46 | Fail-safe-defaults principle prevents systems from failing open. |
CWE-657 | Violation of Secure Design Principles | 20 | Control explicitly requires application of secure design principles throughout the lifecycle. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2025-31200 KEV UPD | 9.9 | 9.8 | 0.1966 | partial |
CVE-2025-6543 KEV UPD | 9.9 | 9.8 | 0.1009 | partial |
CVE-2025-7775 KEV UPD | 9.9 | 9.8 | 0.1963 | partial |
CVE-2025-68615 UPD | 9.2 | 9.8 | 0.4284 | partial |
CVE-2023-6549 KEV UPD | 8.9 | 8.2 | 0.5763 | partial |
CVE-2023-52440 UPD | 8.6 | 9.8 | 0.2191 | partial |
CVE-2026-20700 KEV UPD | 8.5 | 7.8 | 0.0132 | partial |
CVE-2025-7776 UPD | 8.0 | 9.8 | 0.0690 | partial |
CVE-2024-3833 UPD | 7.7 | 8.8 | 0.1756 | partial |
CVE-2024-20082 UPD | 7.6 | 9.8 | 0.0136 | partial |
CVE-2025-43186 UPD | 7.5 | 9.8 | 0.0111 | partial |
CVE-2026-34159 UPD | 7.5 | 9.8 | 0.0113 | partial |
CVE-2026-4149 | 7.5 | 9.8 | 0.0100 | partial |
CVE-2026-8452 | 7.5 | 9.8 | 0.0104 | partial |
CVE-2024-22080 UPD | 7.4 | 9.8 | 0.0078 | partial |
CVE-2024-9401 UPD | 7.4 | 9.8 | 0.0074 | partial |
CVE-2024-9402 UPD | 7.4 | 9.8 | 0.0062 | partial |
CVE-2025-47869 UPD | 7.4 | 9.8 | 0.0065 | partial |
CVE-2025-9179 UPD | 7.4 | 9.8 | 0.0057 | partial |
CVE-2025-29366 UPD | 7.4 | 9.8 | 0.0058 | partial |
CVE-2022-38693 UPD | 7.4 | 9.8 | 0.0080 | partial |
CVE-2022-38696 UPD | 7.4 | 9.8 | 0.0080 | partial |
CVE-2025-43343 UPD | 7.4 | 9.8 | 0.0077 | partial |
CVE-2025-11423 UPD | 7.4 | 9.8 | 0.0079 | partial |
CVE-2026-2773 UPD | 7.4 | 9.8 | 0.0060 | partial |