RONROSSECURE

RONROSSECURERONROSSECURERONROSSECURE
Home
Our Approach
Advisory Services
Research & Insights
Design Principles
Articles
NIST Publications
Speaking & Presentations
Great Cybersecurity Reset
Library
Biography
Contact

RONROSSECURE

RONROSSECURERONROSSECURERONROSSECURE
Home
Our Approach
Advisory Services
Research & Insights
Design Principles
Articles
NIST Publications
Speaking & Presentations
Great Cybersecurity Reset
Library
Biography
Contact
More
  • Home
  • Our Approach
  • Advisory Services
  • Research & Insights
  • Design Principles
  • Articles
  • NIST Publications
  • Speaking & Presentations
  • Great Cybersecurity Reset
  • Library
  • Biography
  • Contact
  • Home
  • Our Approach
  • Advisory Services
  • Research & Insights
  • Design Principles
  • Articles
  • NIST Publications
  • Speaking & Presentations
  • Great Cybersecurity Reset
  • Library
  • Biography
  • Contact

Ron Ross Articles

Workspace promoting Ron Ross' articles on security and technology.

Protecting Mission-Critical Systems

Examines why mission-critical systems require a shift from compliance-focused cybersecurity toward a systems security engineering approach that builds security and resilience into the system throughout its life cycle. Drawing on the NASA/JPL SunRISE pilot, the paper shows how applying NIST SP 800-160 security design principles can improve protection, integrate security with mission engineering, and produce stronger evidence of system trustworthiness.

Read Article

Defending Against Mythos-Class Attacks

Examines how NIST SP 800-160 security design principles can defend mission-critical systems against a new generation of autonomous, AI-driven cyberattacks capable of rapidly discovering and exploiting vulnerabilities. The paper shows how domain separation and complementary structural design principles can contain compromise, disrupt lateral movement, and make damaging attacks structurally difficult rather than merely detectable.

Read Article

Trustworthy Systems Need Trustworthy Parts

Examines a foundational dependency in systems security engineering: trustworthy systems require evidence that the components they depend on are themselves trustworthy. The paper shows how NIST SP 800-160’s trustworthiness principles connect with the Common Criteria to provide rigorous component-level assurance as the evidentiary foundation for system-level trustworthiness.

Read Article

Space System Survivability Against AI-Driven Cyberattacks

Examines how mission-critical space systems can be engineered to survive increasingly sophisticated, AI-driven cyberattacks when vulnerability discovery and patching alone are no longer sufficient. Drawing on NIST SP 800-160 security design principles and results from the NASA/JPL SunRISE pilot, the paper shows how structural security can constrain adversarial movement, contain compromise, and preserve mission resilience by design.

Read Article

Post-Quantum Cryptography (PQC) Transition

Examines why the transition to post-quantum cryptography must be treated as a systems engineering challenge, not simply an algorithm-replacement exercise. The paper shows how NIST SP 800-160 security design principles can turn PQC migration into an opportunity to engineer more trustworthy, crypto-agile, and mission-resilient systems rather than placing stronger cryptography into fundamentally weak architectures.

Read Article

Building Digital Immune Systems

Explores how the human immune system provides a powerful engineering model for building mission-resilient digital systems that can survive adaptive adversaries and inevitable compromise. The paper maps NIST SP 800-160 security design principles and cyber resiliency techniques to biological defenses, showing how systems can be engineered to anticipate, withstand, recover from, and adapt to adversity rather than relying on perfect prevention.

Read Article

AI and the Common Criteria

Examines how artificial intelligence can transform Common Criteria evaluation by making rigorous security assurance faster, more affordable, and increasingly continuous without sacrificing evidence-based rigor. The paper connects AI-enabled Common Criteria evaluation with NIST SP 800-160, showing how stronger component-level assurance can provide the trustworthy building blocks needed to engineer trustworthy secure systems.

Read Article

The Trustworthiness Gap: Why Speed-to-Market Pressure Leaves Security Assurance Behind

Examines how speed-to-market pressures can create a trustworthiness gap by emphasizing requirements and working solutions while shortchanging the evidence needed to justify confidence in system security. Using the NIST SP 800-160 systems security engineering framework, the paper argues that the problem, solution, and trustworthiness contexts must operate together so systems are not merely claimed to be secure, but can demonstrate their trustworthiness through evidence and reasoned assurance.

Read Article

AI Data Centers: The New Center of Gravity

Examines how frontier AI data centers may become a new center of gravity for U.S. national power in future conflict, making their protection a strategic imperative. Drawing on military strategy, NIST SP 800-160, Engineering for Compromise, and RAND research, the paper argues that protection must extend beyond the data center to the power, cooling, communications, facilities, people, and supply chains that sustain national AI capability—so that local defeat cannot become strategic defeat.

Read Article

Adequate Security: An Engineering Answer to an Impossible Question

Examines the fundamental engineering question: How much security does a system really need? Drawing on NIST SP 800-160’s concept of an adequately secure system, the paper explains how minimum tolerable security and as secure as reasonably practicable (ASARP) provide a disciplined basis for answering that question. It argues that security should be determined by mission consequences, system behavior, engineering tradeoffs, and evidence—not by control counts, compliance alone, or the pursuit of perfect security.

Read Article

Engineering the Cyber Defense Surge

Examines OpenAI’s recent call for collective action on cyber defense through the lens of NIST SP 800-160. The paper shows how many capabilities now becoming urgent—including least privilege, defense in depth, containment, resilience, recovery, and evidence-based assurance—have long been foundations of systems security engineering. It argues that the central challenge is the persistent gap between what we have known how to engineer and what organizations have actually built. AI makes closing that gap increasingly urgent.

Read Article

RONROSSECURE, LLC

Copyright © 2026 RONROSSECURE - All Rights Reserved.

Powered by

This website uses cookies.

We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.

Accept