{"data":{"id":"SC-26","name":"Decoys","family":"SC","family_name":"System and Communications Protection","withdrawn":false,"description":"Include components within organizational systems specifically designed to be the target of malicious attacks for detecting, deflecting, and analyzing such attacks.","supplemental_guidance":"Decoys (i.e., honeypots, honeynets, or deception nets) are established to attract adversaries and deflect attacks away from the operational systems that support organizational mission and business functions. Use of decoys requires some supporting isolation measures to ensure that any deflected malicious code does not infect organizational systems. Depending on the specific usage of the decoy, consultation with the Office of the General Counsel before deployment may be needed.","enhancements":[{"id":"SC-26(01)","name":"Detection of Malicious Code","withdrawn":true,"incorporated_into":["SC-35"]}],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"nist_800_53":{"rev5":{"id":"SC-26","name":"Decoys","description":"Include components within organizational systems specifically designed to be the target of malicious attacks for detecting, deflecting, and analyzing such attacks.","discussion":"Decoys (i.e., honeypots, honeynets, or deception nets) are established to attract adversaries and deflect attacks away from the operational systems that support organizational mission and business functions. Use of decoys requires some supporting isolation measures to ensure that any deflected malicious code does not infect organizational systems. Depending on the specific usage of the decoy, consultation with the Office of the General Counsel before deployment may be needed.","related_controls":["RA-05","SC-07","SC-30","SC-35","SC-44","SI-03","SI-04"],"baseline_low":null,"baseline_moderate":null,"baseline_high":null,"baseline_privacy":null,"new_in_rev5":false,"changes_from_rev4":"Title changed from 'Honeypots' to 'Decoys' in Rev 5."}},"compliance_mappings":{"iso_27001_2022":[],"iso_27002_2022":[],"cobit_2019":[],"pci_dss_v4":["11.1","11.4"],"nist_csf_2":[],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":["12"],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":[],"osfi_b13":[],"finma_circular":[],"gdpr":[],"dora":[],"bio2":[],"rbi_csf":["Annex1.13"],"fisc":[],"lgpd_bcb":[],"hkma_tme1":[],"mlps_2":[],"dnb_good_practice":[],"cra":[],"swift_cscf":[],"cbb_tm":["TM-12"],"cbuae":["CR-3"],"qatar_nia":["CS"],"sama_csf":["3.6"],"bom_ctrm":["4.2"],"cbe_csf":["CD-1"],"cbn_csf":["Part3.5","Part4"],"sa_js2":["JS2-7.3"],"bot_cyber":["Ch3.1","Ch8.1"],"cpmi_pfmi":["CG.DE","CG.TE"],"ecb_croe":["CROE.2.4","CROE.2.6.2"],"sebi_cscrf":["DE.CM","SOC"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":["CBEST.4"],"tiber_eu":["TIBER.RT"],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":[],"iso_27799":[],"lloyds_ms":[],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1210","name":"Exploitation of Remote Services","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Deploying decoy systems (honeypots) that emulate vulnerable remote services attracts adversary exploitation attempts, enabling detection of lateral movement and collection of adversary TTPs without risking production systems."},{"id":"T1211","name":"Exploitation for Defense Evasion","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Decoy systems presenting apparent security control weaknesses attract adversary defense evasion exploitation attempts, enabling early detection of exploit techniques and providing intelligence on adversary capabilities."},{"id":"T1212","name":"Exploitation for Credential Access","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Deploying honeypot authentication services that appear to contain credential access vulnerabilities attracts adversary exploitation, enabling detection of credential access techniques and collection of adversary tooling signatures."}],"metadata":{"last_reviewed":"2026-02-19","review_notes":"","mapping_status":"complete"},"function":"detective","used_by_patterns":[]}}