{"data":{"id":"AC-16","name":"Security and Privacy Attributes","family":"AC","family_name":"Access Control","withdrawn":false,"description":"a. Provide the means to associate [Assignment: organization-defined types of security and privacy attributes] with [Assignment: organization-defined security and privacy attribute values] for information in storage, in process, and/or in transmission;\nb. Ensure that the attribute associations are made and retained with the information;\nc. Establish the following permitted security and privacy attributes from the attributes defined in AC-16a for [Assignment: organization-defined systems]: [Assignment: organization-defined security and privacy attributes];\nd. Determine the following permitted attribute values or ranges for each of the established attributes: [Assignment: organization-defined attribute values or ranges for established attributes];\ne. Audit changes to attributes; and\nf. Review [Assignment: organization-defined security and privacy attributes] for applicability [Assignment: organization-defined frequency].","supplemental_guidance":"Information is represented internally within systems using abstractions known as data structures. Internal data structures can represent different types of entities, both active and passive. Active entities, also known as subjects, are typically associated with individuals, devices, or processes acting on behalf of individuals. Passive entities, also known as objects, are typically associated with data structures, such as records, buffers, tables, files, inter-process pipes, and communications ports. Security attributes, a form of metadata, are abstractions that represent the basic properties or characteristics of active and passive entities with respect to safeguarding information. Privacy attributes, which may be used independently or in conjunction with security attributes, represent the basic properties or characteristics of active or passive entities with respect to the management of personally identifiable information. Attributes can be either explicitly or implicitly associated with the information contained in organizational systems or system components.\n\nAttributes may be associated with active entities (i.e., subjects) that have the potential to send or receive information, cause information to flow among objects, or change the system state. These attributes may also be associated with passive entities (i.e., objects) that contain or receive information. The association of attributes to subjects and objects by a system is referred to as binding and is inclusive of setting the attribute value and the attribute type. Attributes, when bound to data or information, permit the enforcement of security and privacy policies for access control and information flow control, including data retention limits, permitted uses of personally identifiable information, and identification of personal information within data objects. Such enforcement occurs through organizational processes or system functions or mechanisms. The binding techniques implemented by systems affect the strength of attribute binding to information. Binding strength and the assurance associated with binding techniques play important parts in the trust that organizations have in the information flow enforcement process. The binding techniques affect the number and degree of additional reviews required by organizations. The content or assigned values of attributes can directly affect the ability of individuals to access organizational information.\n\nOrganizations can define the types of attributes needed for systems to support missions or business functions. There are many values that can be assigned to a security attribute. By specifying the permitted attribute ranges and values, organizations ensure that attribute values are meaningful and relevant. Labeling refers to the association of attributes with the subjects and objects represented by the internal data structures within systems. This facilitates system-based enforcement of information security and privacy policies. Labels include classification of information in accordance with legal and compliance requirements (e.g., top secret, secret, confidential, controlled unclassified), information impact level; high value asset information, access authorizations, nationality; data life cycle protection (i.e., encryption and data expiration), personally identifiable information processing permissions, including individual consent to personally identifiable information processing, and contractor affiliation. A related term to labeling is marking. Marking refers to the association of attributes with objects in a human-readable form and displayed on system media. Marking enables manual, procedural, or process-based enforcement of information security and privacy policies. Security and privacy labels may have the same value as media markings (e.g., top secret, secret, confidential). See MP-03 (Media Marking).","enhancements":[{"id":"AC-16(01)","name":"Dynamic Attribute Association","statement":"Dynamically associate security and privacy attributes with [Assignment: organization-defined subjects and objects] in accordance with the following security and privacy policies as information is created and combined: [Assignment: organization-defined security and privacy policies].","baselines":[]},{"id":"AC-16(02)","name":"Attribute Value Changes by Authorized Individuals","statement":"Provide authorized individuals (or processes acting on behalf of individuals) the capability to define or change the value of associated security and privacy attributes.","baselines":[]},{"id":"AC-16(03)","name":"Maintenance of Attribute Associations by System","statement":"Maintain the association and integrity of [Assignment: organization-defined security and privacy attributes] to [Assignment: organization-defined subjects and objects].","baselines":[]},{"id":"AC-16(04)","name":"Association of Attributes by Authorized Individuals","statement":"Provide the capability to associate [Assignment: organization-defined security and privacy attributes] with [Assignment: organization-defined subjects and objects] by authorized individuals (or processes acting on behalf of individuals).","baselines":[]},{"id":"AC-16(05)","name":"Attribute Displays on Objects to Be Output","statement":"Display security and privacy attributes in human-readable form on each object that the system transmits to output devices to identify [Assignment: organization-defined special dissemination, handling, or distribution instructions] using [Assignment: organization-defined human-readable, standard naming conventions].","baselines":[]},{"id":"AC-16(06)","name":"Maintenance of Attribute Association","statement":"Require personnel to associate and maintain the association of [Assignment: organization-defined security and privacy attributes] with [Assignment: organization-defined subjects and objects] in accordance with [Assignment: organization-defined security and privacy policies].","baselines":[]},{"id":"AC-16(07)","name":"Consistent Attribute Interpretation","statement":"Provide a consistent interpretation of security and privacy attributes transmitted between distributed system components.","baselines":[]},{"id":"AC-16(08)","name":"Association Techniques and Technologies","statement":"Implement [Assignment: organization-defined techniques and technologies] in associating security and privacy attributes to information.","baselines":[]},{"id":"AC-16(09)","name":"Attribute Reassignment — Regrading Mechanisms","statement":"Change security and privacy attributes associated with information only via regrading mechanisms validated using [Assignment: organization-defined techniques or procedures].","baselines":[]},{"id":"AC-16(10)","name":"Attribute Configuration by Authorized Individuals","statement":"Provide authorized individuals the capability to define or change the type and value of security and privacy attributes available for association with subjects and objects.","baselines":[]}],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"nist_800_53":{"rev5":{"id":"AC-16","name":"Security and Privacy Attributes","description":"a. Provide the means to associate [Assignment: organization-defined types of security and privacy attributes] with [Assignment: organization-defined security and privacy attribute values] for information in storage, in process, and/or in transmission;\nb. Ensure that the attribute associations are made and retained with the information;\nc. Establish the following permitted security and privacy attributes from the attributes defined in AC-16a for [Assignment: organization-defined systems]: [Assignment: organization-defined security and privacy attributes];\nd. Determine the following permitted attribute values or ranges for each of the established attributes: [Assignment: organization-defined attribute values or ranges for established attributes];\ne. Audit changes to attributes; and\nf. Review [Assignment: organization-defined security and privacy attributes] for applicability [Assignment: organization-defined frequency].","discussion":"Information is represented internally within systems using abstractions known as data structures. Internal data structures can represent different types of entities, both active and passive. Active entities, also known as subjects, are typically associated with individuals, devices, or processes acting on behalf of individuals. Passive entities, also known as objects, are typically associated with data structures, such as records, buffers, tables, files, inter-process pipes, and communications ports. Security attributes, a form of metadata, are abstractions that represent the basic properties or characteristics of active and passive entities with respect to safeguarding information. Privacy attributes, which may be used independently or in conjunction with security attributes, represent the basic properties or characteristics of active or passive entities with respect to the management of personally identifiable information. Attributes can be either explicitly or implicitly associated with the information contained in organizational systems or system components.\n\nAttributes may be associated with active entities (i.e., subjects) that have the potential to send or receive information, cause information to flow among objects, or change the system state. These attributes may also be associated with passive entities (i.e., objects) that contain or receive information. The association of attributes to subjects and objects by a system is referred to as binding and is inclusive of setting the attribute value and the attribute type. Attributes, when bound to data or information, permit the enforcement of security and privacy policies for access control and information flow control, including data retention limits, permitted uses of personally identifiable information, and identification of personal information within data objects. Such enforcement occurs through organizational processes or system functions or mechanisms. The binding techniques implemented by systems affect the strength of attribute binding to information. Binding strength and the assurance associated with binding techniques play important parts in the trust that organizations have in the information flow enforcement process. The binding techniques affect the number and degree of additional reviews required by organizations. The content or assigned values of attributes can directly affect the ability of individuals to access organizational information.\n\nOrganizations can define the types of attributes needed for systems to support missions or business functions. There are many values that can be assigned to a security attribute. By specifying the permitted attribute ranges and values, organizations ensure that attribute values are meaningful and relevant. Labeling refers to the association of attributes with the subjects and objects represented by the internal data structures within systems. This facilitates system-based enforcement of information security and privacy policies. Labels include classification of information in accordance with legal and compliance requirements (e.g., top secret, secret, confidential, controlled unclassified), information impact level; high value asset information, access authorizations, nationality; data life cycle protection (i.e., encryption and data expiration), personally identifiable information processing permissions, including individual consent to personally identifiable information processing, and contractor affiliation. A related term to labeling is marking. Marking refers to the association of attributes with objects in a human-readable form and displayed on system media. Marking enables manual, procedural, or process-based enforcement of information security and privacy policies. Security and privacy labels may have the same value as media markings (e.g., top secret, secret, confidential). See MP-03 (Media Marking).","related_controls":["AC-03","AC-04","AC-06","AC-21","AC-25","AU-02","AU-10","MP-03","PE-22","PT-02","PT-03","PT-04","SC-11","SC-16","SI-12","SI-18"],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"Title changed from 'Security Attributes' Adds privacy to parameters Adds control text for auditing changes to attributes Adds control text and parameters for reviewing security and privacy attributes at a specified frequency Discussion includes new attributes and incorporates discussion about security attribute binding from withdrawn control AC-04(18)"}},"compliance_mappings":{"iso_27001_2022":["A.5.13"],"iso_27002_2022":["5.12","5.13"],"cobit_2019":["DSS05"],"pci_dss_v4":[],"nist_csf_2":["PR.AA-05"],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":["CCC-C16"],"iso_42001_2023":["A.7.4","A.7.5"],"iec_62443":[],"asd_e8":[],"nis2":["Art. 21(2)(i)"],"apra_cps_234":[],"mas_trm":["9"],"pra_op_resilience":[],"bsi_grundschutz":["ORP.4"],"anssi":["Hygiene.8"],"osfi_b13":["B-13.3.2"],"finma_circular":["IV.D(78)","IV.D(79)","IV.D(80)"],"gdpr":["Art.5(1)(e)","Art.9(1)"],"dora":["Art.8(1)","Art.8(4)"],"bio2":["5.12","5.13"],"rbi_csf":[],"fisc":["FISC.O9","FISC.T5"],"lgpd_bcb":["LGPD.Art.11"],"hkma_tme1":["TME1.7.2"],"mlps_2":[],"dnb_good_practice":["DNB.2.2","DNB.6.1","DNB.12.3"],"cra":[],"swift_cscf":[],"cbb_tm":["TM-6","TM-9"],"cbuae":["CR-5"],"nca_ecc":["2-7"],"qatar_nia":["AC","AM"],"sama_csf":["3.1"],"uae_ia":["T4","T9"],"bog_cisd":["CISD-V"],"cbe_csf":["CTO-2"],"cbn_csf":["Part3.4"],"popia":["s26-27","s28-33"],"sa_js2":["JS2-6.1"],"bcbs_239":["Principle 11"],"bot_cyber":["Ch2.2"],"iosco_cyber":["ID-4"],"cmmc_2":["AC"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":["CC Part 2 — FDP"],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":["§11.10(g)"],"fda_cyber":[],"hitrust_csf":["07.b"],"iso_27799":["5.3","8.2"],"lloyds_ms":["MS7.1","MS8.7"],"naic_ds":[],"nhs_dspt":["NDG-4.4"],"pra_ss1_23":[],"solvency_ii":["DR.266-DataSec","EIOPA-ICT-4.3"],"owasp_masvs_v2":[],"csa_ccm_v4":["DSP-04","DSP-06","IAM-16"],"csa_aicm":["DSP-04","DSP-06","IAM-16"],"ccss_v9":[],"mica":[],"basel_sco60":["SCO60.70"],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1003","name":"OS Credential Dumping","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Automated labelling of credential stores as high-sensitivity assets triggers enhanced DLP controls and access restrictions, making it harder for adversaries to extract and exfiltrate dumped credentials without triggering classification-aware security alerts."},{"id":"T1005","name":"Data from Local System","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Information labelling enables DLP systems to detect and block unauthorized collection of classified local data, as sensitivity tags on files trigger policy enforcement when adversaries attempt to stage or move labelled information outside approved boundaries."},{"id":"T1025","name":"Data from Removable Media","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Automated classification labels on data stored on removable media enable endpoint DLP controls to detect and prevent unauthorized copying or access to sensitive information from portable storage devices."},{"id":"T1040","name":"Network Sniffing","tactics":["credential-access","discovery"],"mapping_type":"mitigates","mapping_rationale":"Labelling sensitive data in transmission enables network DLP to detect when classified information traverses network segments in cleartext, alerting on credential material and sensitive data that should not be visible to network sniffing."},{"id":"T1041","name":"Exfiltration Over C2 Channel","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Automated information labelling enables DLP systems to identify and block exfiltration of classified data over C2 channels, as sensitivity tags trigger policy enforcement when labelled content is detected in outbound command-and-control traffic."},{"id":"T1048","name":"Exfiltration Over Alternative Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Classification labels on sensitive data enable DLP controls to detect and block exfiltration attempts over alternative protocols, as labelled information triggers policy alerts regardless of the transport protocol used for data extraction."},{"id":"T1052","name":"Exfiltration Over Physical Medium","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Automated labelling of sensitive information enables endpoint DLP controls to detect and block attempts to copy classified data to physical media, preventing exfiltration over USB drives or other removable devices."},{"id":"T1070","name":"Indicator Removal","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Labelling system audit outputs as retention-critical enables policy enforcement that prevents deletion or modification of classified log data, making adversary indicator removal attempts trigger tamper detection alerts on labelled audit records."},{"id":"T1114","name":"Email Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Automated classification of email content enables DLP systems to detect bulk email collection activities, triggering alerts when labelled sensitive messages are accessed, forwarded, or exported in patterns consistent with adversary email harvesting."},{"id":"T1119","name":"Automated Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Information labelling enables automated DLP controls to detect and alert on bulk collection of classified data, as sensitivity tags on files and records trigger policy enforcement when large volumes of labelled content are accessed or staged."},{"id":"T1213","name":"Data from Information Repositories","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Classification labels on information repository content enable access control and DLP policies that restrict bulk data extraction from wikis, document management systems, and collaboration platforms based on data sensitivity levels."},{"id":"T1222","name":"File and Directory Permissions Modification","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Labelling sensitive files and directories enables detection of unauthorized permission changes, as automated controls alert when adversaries modify access permissions on classified data objects to facilitate broader access or weaken security postures."},{"id":"T1505","name":"Server Software Component","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Automated labelling of server software components and configuration files enables integrity monitoring that detects unauthorized additions or modifications, alerting when adversaries install persistent server components that alter labelled system files."},{"id":"T1530","name":"Data from Cloud Storage","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Classification labels on cloud storage objects enable cloud DLP policies that restrict access based on sensitivity levels, detecting and alerting when adversaries attempt to access or download labelled data from cloud storage repositories."},{"id":"T1537","name":"Transfer Data to Cloud Account","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Automated data labelling enables cloud DLP controls to detect and block attempts to transfer classified data to external cloud accounts, as sensitivity tags trigger policy enforcement on cross-account data movement operations."},{"id":"T1548","name":"Abuse Elevation Control Mechanism","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Labelling privilege-escalation-relevant system components enables enhanced monitoring and integrity controls that detect abuse of elevation control mechanisms when adversaries attempt to modify or misuse classified authorization artifacts."},{"id":"T1552","name":"Unsecured Credentials","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Automated labelling of credential material—including keys, certificates, and password files—enables DLP controls that alert on unauthorized access patterns and block exfiltration of classified credential data from the environment."},{"id":"T1557","name":"Adversary-in-the-Middle","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Information labelling in transmission enables detection of adversary-in-the-middle interception, as classification-aware network controls can identify when labelled sensitive data appears in unexpected network locations or traverses unauthorized network paths."},{"id":"T1558","name":"Steal or Forge Kerberos Tickets","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Labelling Kerberos credential materials and ticket caches as high-sensitivity assets enables enhanced monitoring and access controls that detect unauthorized access to or export of classified authentication tokens and keytab files."},{"id":"T1565","name":"Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Automated integrity labelling of critical data enables tamper detection by establishing authoritative classification metadata that reveals unauthorized modifications, as changes to labelled data trigger integrity verification and alert workflows."},{"id":"T1567","name":"Exfiltration Over Web Service","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Classification labels enable DLP controls to detect and block exfiltration of sensitive data over web services such as cloud storage, code repositories, and file sharing platforms, regardless of the specific web service used."},{"id":"T1602","name":"Data from Configuration Repository","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Labelling network device configuration data as sensitive enables DLP controls that detect unauthorized access to or export of classified configuration repositories, alerting when management data is collected outside approved workflows."},{"id":"T1647","name":"Plist File Modification","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Automated labelling of system property list files enables integrity monitoring that detects unauthorized plist modifications, alerting when adversaries alter labelled macOS configuration files to achieve defense evasion or persistence."},{"id":"T1003.003","name":"NTDS","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Labelling the NTDS.dit database and its backups as critical credential stores triggers enhanced DLP and access controls, making unauthorized extraction or copying of the Active Directory database detectable through classification-aware monitoring."},{"id":"T1020.001","name":"Traffic Duplication","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Information labelling in transmission enables detection of unauthorized traffic duplication, as classification-aware network monitoring identifies when labelled sensitive data appears in duplicated traffic streams destined for unauthorized collection points."},{"id":"T1048.002","name":"Exfiltration Over Asymmetric Encrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Automated data labelling enables DLP controls to detect classified information being exfiltrated over asymmetric encrypted alternative protocols, triggering policy enforcement regardless of the encryption applied to the exfiltration channel."},{"id":"T1048.003","name":"Exfiltration Over Unencrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Classification labels on sensitive data enable DLP systems to detect and block exfiltration over unencrypted protocols, with labelled content in cleartext network streams triggering immediate policy enforcement and alerting."},{"id":"T1052.001","name":"Exfiltration over USB","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Automated labelling enables endpoint DLP controls to detect and block USB exfiltration of classified data, as sensitivity tags on files trigger write-blocking policies when labelled content is copied to removable USB devices."},{"id":"T1070.001","name":"Clear Windows Event Logs","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Labelling Windows event logs as retention-critical assets triggers tamper-detection controls that alert when adversaries attempt to clear classified audit records, and enforces protective policies that prevent deletion of labelled log data."},{"id":"T1070.002","name":"Clear Linux or Mac System Logs","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Classification of Linux and macOS system logs as retention-critical enables automated controls that detect and alert on attempts to clear labelled audit records, preserving evidence integrity through classification-aware tamper detection."},{"id":"T1070.008","name":"Clear Mailbox Data","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Labelling mailbox data according to sensitivity enables retention controls that detect and alert on bulk mailbox deletion, making adversary attempts to clear classified email evidence triggering compliance and security alerts."},{"id":"T1114.001","name":"Local Email Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Automated labelling of local email data enables endpoint DLP controls that detect and alert on unauthorized access to classified messages, making local email collection activities visible when adversaries interact with labelled content."},{"id":"T1114.002","name":"Remote Email Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Classification labels on email content enable server-side DLP policies that detect unauthorized remote email collection, alerting when bulk access to labelled sensitive messages occurs via compromised credentials or delegated access."},{"id":"T1114.003","name":"Email Forwarding Rule","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Labelling sensitive email content enables DLP controls that detect and block email forwarding rules targeting classified messages, alerting when adversaries create auto-forwarding rules that would exfiltrate labelled information to external addresses."},{"id":"T1213.001","name":"Confluence","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Classification labels on Confluence content enable DLP policies that restrict bulk export of labelled pages and detect unauthorized data collection from wiki spaces containing classified information."},{"id":"T1213.002","name":"Sharepoint","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Automated labelling of SharePoint content enables DLP controls that detect and alert on bulk download or extraction of classified documents, blocking adversary attempts to harvest sensitive data from labelled document libraries."},{"id":"T1213.004","name":"Customer Relationship Management Software","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Classification labels on CRM data enable access controls and DLP policies that detect unauthorized bulk extraction of labelled customer records, alerting when adversaries collect classified business data from CRM platforms."},{"id":"T1213.005","name":"Messaging Applications","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Automated labelling of messaging application content enables DLP controls that detect unauthorized collection of classified messages, alerting when adversaries access or export labelled sensitive conversations from collaboration platforms."},{"id":"T1222.001","name":"Windows File and Directory Permissions Modification","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Classification labels on Windows files and directories enable detection of unauthorized permission modifications, alerting when adversaries change ACLs on labelled sensitive objects to weaken access controls and facilitate data collection."},{"id":"T1222.002","name":"Linux and Mac File and Directory Permissions Modification","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Labelling sensitive Linux and macOS files enables detection of unauthorized permission changes via chmod or chown operations on classified data, triggering security alerts when adversaries modify access controls on labelled objects."},{"id":"T1505.002","name":"Transport Agent","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Automated labelling of mail transport agent configurations enables integrity monitoring that detects unauthorized transport agent installations, alerting when adversaries modify labelled Exchange or mail server components for persistent access."},{"id":"T1547.007","name":"Re-opened Applications","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Classification labels on application state files enable detection of unauthorized modifications to re-opened application lists, alerting when adversaries alter labelled macOS application persistence mechanisms to achieve automatic execution."},{"id":"T1548.003","name":"Sudo and Sudo Caching","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Labelling sudoers files and sudo configuration as high-security assets enables monitoring that detects unauthorized modifications to classified elevation control mechanisms, alerting on sudo caching abuse or sudoers file tampering."},{"id":"T1548.006","name":"TCC Manipulation","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Automated labelling of TCC database files as security-critical enables integrity monitoring that detects unauthorized manipulation of macOS transparency, consent, and control frameworks by alerting on modifications to labelled privacy databases."},{"id":"T1550.001","name":"Application Access Token","tactics":["defense-evasion","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Classification of application access tokens as sensitive credentials enables DLP and monitoring controls that detect unauthorized token usage patterns, alerting when labelled tokens are used from unexpected contexts or locations."},{"id":"T1552.004","name":"Private Keys","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Automated labelling of private key files as high-sensitivity assets enables DLP controls that detect unauthorized access, copying, or exfiltration of labelled cryptographic keys from file systems and key management repositories."},{"id":"T1552.005","name":"Cloud Instance Metadata API","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Classification of cloud instance metadata as sensitive enables monitoring controls that detect unauthorized access to labelled metadata API endpoints, alerting when adversaries query cloud credential sources from unexpected compute instances."},{"id":"T1556.009","name":"Conditional Access Policies","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Labelling conditional access policy configurations as security-critical enables change detection and integrity monitoring that alerts when adversaries modify labelled authentication policies to weaken or bypass conditional access enforcement."},{"id":"T1557.002","name":"ARP Cache Poisoning","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Information labelling in transit enables detection of ARP cache poisoning interception, as classification-aware network controls identify when labelled sensitive data appears in traffic flows traversing unexpected network paths indicative of MITM attacks."},{"id":"T1558.002","name":"Silver Ticket","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Labelling service account credentials and Kerberos service keys as high-sensitivity assets enables enhanced monitoring that detects unauthorized access to the materials needed for silver ticket forgery, triggering alerts on labelled credential access."},{"id":"T1558.003","name":"Kerberoasting","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Classification of service principal name credentials as sensitive enables monitoring controls that detect Kerberoasting reconnaissance, alerting when high-volume TGS requests target labelled service accounts indicative of offline password cracking attempts."},{"id":"T1558.004","name":"AS-REP Roasting","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Automated labelling of accounts with pre-authentication settings enables monitoring that detects AS-REP roasting attempts, alerting when authentication requests target labelled accounts configured without Kerberos pre-authentication requirements."},{"id":"T1564.004","name":"NTFS File Attributes","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Classification-aware file systems that label all data attributes—including NTFS alternate data streams—enable detection of hidden content that adversaries store in extended file attributes to evade conventional file-based security scanning."},{"id":"T1565.001","name":"Stored Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Automated integrity labelling creates authoritative metadata that enables detection of stored data manipulation, as modifications to labelled data trigger integrity verification workflows that compare current content against classification-protected baselines."},{"id":"T1565.002","name":"Transmitted Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Classification labels on transmitted data enable integrity monitoring that detects in-transit data manipulation, as DLP controls verify that labelled content arriving at its destination matches the expected classification and integrity markers."},{"id":"T1602.001","name":"SNMP (MIB Dump)","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Labelling SNMP management data as sensitive enables monitoring controls that detect unauthorized MIB collection activities, alerting when adversaries access labelled network configuration data through SNMP queries outside approved management workflows."},{"id":"T1602.002","name":"Network Device Configuration Dump","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Classification of network device configuration data as sensitive enables DLP controls that detect unauthorized configuration dumps, alerting when labelled management data is exported or accessed outside approved change management procedures."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: nist_csf_2 PR.AA-05 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base. 2026-10-03: baselines LMH to ---, from NIST SP 800-53B Release 5.2.0.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-013","SP-044","SP-052"]}}