{"data":{"id":"SC-24","name":"Fail in Known State","family":"SC","family_name":"System and Communications Protection","withdrawn":false,"description":"Fail to a [Assignment: organization-defined known system state] for the following failures on the indicated components while preserving [Assignment: organization-defined system state information] in failure: [Assignment: list of organization-defined types of system failures on organization-defined system components].","supplemental_guidance":"Failure in a known state addresses security concerns in accordance with the mission and business needs of organizations. Failure in a known state prevents the loss of confidentiality, integrity, or availability of information in the event of failures of organizational systems or system components. Failure in a known safe state helps to prevent systems from failing to a state that may cause injury to individuals or destruction to property. Preserving system state information facilitates system restart and return to the operational mode with less disruption of mission and business processes.","enhancements":[],"baseline_low":false,"baseline_moderate":false,"baseline_high":true,"nist_800_53":{"rev5":{"id":"SC-24","name":"Fail in Known State","description":"Fail to a [Assignment: organization-defined known system state] for the following failures on the indicated components while preserving [Assignment: organization-defined system state information] in failure: [Assignment: list of organization-defined types of system failures on organization-defined system components].","discussion":"Failure in a known state addresses security concerns in accordance with the mission and business needs of organizations. Failure in a known state prevents the loss of confidentiality, integrity, or availability of information in the event of failures of organizational systems or system components. Failure in a known safe state helps to prevent systems from failing to a state that may cause injury to individuals or destruction to property. Preserving system state information facilitates system restart and return to the operational mode with less disruption of mission and business processes.","related_controls":["CP-02","CP-04","CP-10","CP-12","SA-08","SC-07","SC-22","SI-13"],"baseline_low":null,"baseline_moderate":null,"baseline_high":true,"baseline_privacy":null,"new_in_rev5":false,"changes_from_rev4":"No significant title changes from Rev 4."}},"compliance_mappings":{"iso_27001_2022":[],"iso_27002_2022":[],"cobit_2019":["DSS05"],"pci_dss_v4":["10.7"],"nist_csf_2":["PR.DS-10","PR.IR-03"],"cis_controls_v8":[],"soc2_tsc":["A1.2","CC7.4-POF5"],"finos_ccc":[],"iso_42001_2023":["A.4.5"],"iec_62443":["3-3 SR 7.1","3-3 SR 7.4"],"asd_e8":[],"nis2":["Art. 21(2)(c)"],"apra_cps_234":[],"mas_trm":["8"],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":[],"osfi_b13":["B-13.2.6"],"finma_circular":["IV.B.d(59)","IV.C(61)","IV.C(70)","IV.D(71)","IV.E(87)","IV.E(89)","IV.E(90)"],"gdpr":["Art.32(1)(b)"],"dora":["Art.9(2)","Art.11(4)","Art.12(2)"],"bio2":[],"rbi_csf":["Annex1.4"],"fisc":["FISC.O5"],"lgpd_bcb":["BCB.Art.7"],"hkma_tme1":["TME1.6.2"],"mlps_2":[],"dnb_good_practice":[],"cra":["CRA.I.2k"],"swift_cscf":[],"cbb_tm":["TM-14"],"cbuae":["CR-13"],"nca_ecc":["3-1","3-2","5-1"],"bog_cisd":["CISD-BCM"],"bom_ctrm":["5.2"],"cbe_csf":["OVM-2"],"cbn_csf":["Part3.7"],"sa_js2":["JS2-7.5"],"bcbs_239":["Principle 5"],"bot_cyber":["Ch4.2"],"cpmi_pfmi":["CG.RR"],"eba_ict":["3.7.3"],"ecb_croe":["CROE.2.5.2"],"iosco_cyber":["PFMI-17","RR-2","RR-3"],"sebi_cscrf":["RC.RP"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":["Sec 8"],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":["CC Part 2 — FPT"],"isae_3402":[],"fca_sysc_13":["SYSC 13.8.2"],"fda_21_cfr_11":[],"fda_cyber":["SA-6"],"hitrust_csf":[],"iso_27799":[],"lloyds_ms":["MS8.6"],"naic_ds":[],"nhs_dspt":["NDG-7.4"],"pra_ss1_23":[],"solvency_ii":["EIOPA-ICT-4.10"],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: nist_csf_2 PR.DS-10, PR.IR-03 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"preventative","used_by_patterns":[]}}