Engineering Trustworthy Secure Systems
Security engineered for sophisticated adversaries, compromise, and failure.
Engineering Trustworthy Secure Systems
Security engineered for sophisticated adversaries, compromise, and failure.
Security engineered for sophisticated adversaries, compromise, and failure.
Security engineered for sophisticated adversaries, compromise, and failure.

Traditional cybersecurity remains essential, but controls and operational defenses alone may be insufficient for high-consequence systems facing sophisticated adversaries.
Systems security engineering begins with the mission, the assets that must be protected, the consequences of their loss, and the capabilities of the adversary. Security is then engineered into the architecture—constraining privilege, information flow, functionality, trust, and the propagation of compromise.
The objective is not simply to prevent every compromise. It is to engineer systems in which compromise does not automatically become catastrophic loss.

Practical support for applying NIST SP 800-160 to engineer trustworthy secure and resilient systems. Focus areas include systems security engineering, architecture reviews, design principles, assurance strategy, and resilience engineering.

Advisory services for building and demonstrating trust and resilience in high-consequence systems. Focus areas include assurance cases, continuous assurance, risk management, and preparing for compromise and failure.

Executive leadership guidance for mission-critical systems facing sophisticated adversaries, accelerating technology change, and increasing systemic risk. Focus areas include strategy, governance, risk, resilience, and trust at enterprise scale.

Technical research, education, and expert support across systems security engineering, cyber resilience, cryptographic resilience, assurance, and trustworthy AI. Includes speaking, training, expert witness, and tailored engagements.
Carl Landwehr

A systems security engineering approach for designing trustworthy, resilient systems that anticipate compromise, constrain its propagation, and prevent catastrophic loss.
Applying systems security engineering principles to high-assurance AI systems and infrastructure for protecting critical AI assets against sophisticated adversaries.
Engineering the capability to adapt cryptography faster than adversaries can operationalize emerging threats in an AI-accelerated, post-quantum era.
Designing systems to anticipate, withstand, recover from, and adapt to adverse conditions while continuing to deliver essential functions.

A 30-part series examining the security design principles in NIST SP 800-160, Volume 1, Revision 1—what they mean, why they matter, and how they can be applied to systems facing sophisticated adversaries, compromise, and failure.
Domain Separation establishes security boundaries that limit the propagation of compromise across system elements. This article examines how separation of domains, resources, and privileges can contain adversary effects and preserve critical system functions when portions of a system are compromised.
Trust boundaries are only effective when interactions across them are controlled. Mediated Access ensures that every security-relevant interaction is subject to explicit policy enforcement, preventing unauthorized access and limiting the pathways through which compromise can propagate.

Examines why mission-critical systems require a shift from compliance-focused cybersecurity toward a systems security engineering approach that builds security and resilience into the system throughout its life cycle. Drawing on the NASA/JPL SunRISE pilot, the paper shows how applying NIST SP 800-160 security design principles can improve protection, integrate security with mission engineering, and produce stronger evidence of system trustworthiness.
Examines how NIST SP 800-160 security design principles can defend mission-critical systems against a new generation of autonomous, AI-driven cyberattacks capable of rapidly discovering and exploiting vulnerabilities. The paper shows how domain separation and complementary structural design principles can contain compromise, disrupt lateral movement, and make damaging attacks structurally difficult rather than merely detectable.
Examines a foundational dependency in systems security engineering: trustworthy systems require evidence that the components they depend on are themselves trustworthy. The paper shows how NIST SP 800-160’s trustworthiness principles connect with the Common Criteria to provide rigorous component-level assurance as the evidentiary foundation for system-level trustworthiness.
Examines how mission-critical space systems can be engineered to survive increasingly sophisticated, AI-driven cyberattacks when vulnerability discovery and patching alone are no longer sufficient. Drawing on NIST SP 800-160 security design principles and results from the NASA/JPL SunRISE pilot, the paper shows how structural security can constrain adversarial movement, contain compromise, and preserve mission resilience by design.
Examines why the transition to post-quantum cryptography must be treated as a systems engineering challenge, not simply an algorithm-replacement exercise. The paper shows how NIST SP 800-160 security design principles can turn PQC migration into an opportunity to engineer more trustworthy, crypto-agile, and mission-resilient systems rather than placing stronger cryptography into fundamentally weak architectures.
Explores how the human immune system provides a powerful engineering model for building mission-resilient digital systems that can survive adaptive adversaries and inevitable compromise. The paper maps NIST SP 800-160 security design principles and cyber resiliency techniques to biological defenses, showing how systems can be engineered to anticipate, withstand, recover from, and adapt to adversity rather than relying on perfect prevention.
Examines how artificial intelligence can transform Common Criteria evaluation by making rigorous security assurance faster, more affordable, and increasingly continuous without sacrificing evidence-based rigor. The paper connects AI-enabled Common Criteria evaluation with NIST SP 800-160, showing how stronger component-level assurance can provide the trustworthy building blocks needed to engineer trustworthy secure systems.
Examines how speed-to-market pressures can create a trustworthiness gap by emphasizing requirements and working solutions while shortchanging the evidence needed to justify confidence in system security. Using the NIST SP 800-160 systems security engineering framework, the paper argues that the problem, solution, and trustworthiness contexts must operate together so systems are not merely claimed to be secure, but can demonstrate their trustworthiness through evidence and reasoned assurance.
Examines how frontier AI data centers may become a new center of gravity for U.S. national power in future conflict, making their protection a strategic imperative. Drawing on military strategy, NIST SP 800-160, Engineering for Compromise, and RAND research, the paper argues that protection must extend beyond the data center to the power, cooling, communications, facilities, people, and supply chains that sustain national AI capability—so that local defeat cannot become strategic defeat.
Examines the fundamental engineering question: How much security does a system really need? Drawing on NIST SP 800-160’s concept of an adequately secure system, the paper explains how minimum tolerable security and as secure as reasonably practicable (ASARP) provide a disciplined basis for answering that question. It argues that security should be determined by mission consequences, system behavior, engineering tradeoffs, and evidence—not by control counts, compliance alone, or the pursuit of perfect security.

October 27-28, 2026, Delft, Amsterdam
Presentation: Supply and Demand for Systems Security Engineering Competencies

October 14, 2026 (Virtual)
Fireside Chat: Engineering Resilience in the Age of AI

Security and Privacy Controls for Information Systems and Organizations
Available free of charge on the NIST website
Assessing Security and Privacy Controls in Information Systems and Organizations
Available free of charge on the NIST website
Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
Available free of charge on the NIST website
Assessing Security Requirements for Controlled Unclassified Information
Available free of charge on the NIST website
Enhanced Security Requirements for Protecting Controlled Unclassified Information
Available free of charge on the NIST website
Assessing Enhanced Security Requirements for Protecting Controlled Unclassified Information
Available free of charge on the NIST website
Engineering Trustworthy Secure Systems
Available free of charge on the NIST website
Developing Cyber Resilient Systems
Available free of charge on the NIST website
Risk Management Framework for Information Systems and Organizations
Available free of charge on the NIST website
Managing Information Security Risk: Organization, Mission, and System View
Available free of charge on the NIST website
Guide for Conducting Risk Assessments
Available free of charge on the NIST website
Standards for Security Categorization of Federal Information and Information Systems
Available free of charge on the NIST website
https://doi.org/10.6028/NIST.FIPS.199
Minimum Security Requirements for Federal Information and Information Systems
Available free of charge on the NIST website
General Michael Hayden
Introduction to the TSSE Ecosystem
Download PDFWe use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.