HomeControl Library › 3.13.2
3.13 System & Communications Protection5 pts

3.13.2 — Build security in by design

Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.

Don't bolt security on at the end — design, build, and configure systems with security as a first-class requirement.

What it actually means

This control asks you to use sound architecture and engineering practices so security is part of how systems are designed and built, not an afterthought. For a small contractor that usually means a documented network and data-flow architecture, secure baseline configurations, a deliberate boundary around CUI, and following vendor security best-practice guidance when you stand systems up. You don't need a formal software development lifecycle — you need evidence that your security decisions are intentional and written down.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

This is a 5-point control and is generally not POA&M-eligible — but the bar is 'deliberate and documented,' not 'enterprise-grade.' A clear architecture diagram and baseline standard go a long way.

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library