{"data":{"id":"SC-29","name":"Heterogeneity","family":"SC","family_name":"System and Communications Protection","withdrawn":false,"description":"Employ a diverse set of information technologies for the following system components in the implementation of the system: [Assignment: organization-defined system components].","supplemental_guidance":"Increasing the diversity of information technologies within organizational systems reduces the impact of potential exploitations or compromises of specific technologies. Such diversity protects against common mode failures, including those failures induced by supply chain attacks. Diversity in information technologies also reduces the likelihood that the means adversaries use to compromise one system component will be effective against other system components, thus further increasing the adversary work factor to successfully complete planned attacks. An increase in diversity may add complexity and management overhead that could ultimately lead to mistakes and unauthorized configurations.","enhancements":[{"id":"SC-29(01)","name":"Virtualization Techniques","statement":"Employ virtualization techniques to support the deployment of a diversity of operating systems and applications that are changed [Assignment: organization-defined frequency].","baselines":[]}],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"nist_800_53":{"rev5":{"id":"SC-29","name":"Heterogeneity","description":"Employ a diverse set of information technologies for the following system components in the implementation of the system: [Assignment: organization-defined system components].","discussion":"Increasing the diversity of information technologies within organizational systems reduces the impact of potential exploitations or compromises of specific technologies. Such diversity protects against common mode failures, including those failures induced by supply chain attacks. Diversity in information technologies also reduces the likelihood that the means adversaries use to compromise one system component will be effective against other system components, thus further increasing the adversary work factor to successfully complete planned attacks. An increase in diversity may add complexity and management overhead that could ultimately lead to mistakes and unauthorized configurations.","related_controls":["AU-09","PL-08","SC-27","SC-30","SR-03"],"baseline_low":null,"baseline_moderate":null,"baseline_high":null,"baseline_privacy":null,"new_in_rev5":false,"changes_from_rev4":"No significant title changes from Rev 4."}},"compliance_mappings":{"iso_27001_2022":[],"iso_27002_2022":[],"cobit_2019":[],"pci_dss_v4":[],"nist_csf_2":[],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":[],"osfi_b13":[],"finma_circular":[],"gdpr":[],"dora":[],"bio2":[],"rbi_csf":["Annex1.4"],"fisc":[],"lgpd_bcb":[],"hkma_tme1":[],"mlps_2":[],"dnb_good_practice":[],"cra":["CRA.I.2k"],"swift_cscf":[],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":[],"iso_27799":[],"lloyds_ms":[],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1189","name":"Drive-by Compromise","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Deploying heterogeneous browser and client technologies across the enterprise limits the blast radius of drive-by compromise attacks, as exploits targeting a specific browser or plugin version will only succeed against a subset of the organisation's endpoints."},{"id":"T1190","name":"Exploit Public-Facing Application","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Technology diversity in public-facing applications—using different web servers, frameworks, and operating systems—prevents a single vulnerability from providing adversaries with uniform initial access across all internet-exposed services."},{"id":"T1203","name":"Exploitation for Client Execution","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"A diverse client software ecosystem ensures that exploits targeting a specific application vulnerability for code execution affect only a fraction of endpoints, limiting the adversary's ability to achieve widespread client-side exploitation."},{"id":"T1210","name":"Exploitation of Remote Services","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Heterogeneous operating systems and service implementations across network segments mean that remote service exploits effective against one platform cannot be reused for lateral movement to systems running different technology stacks."},{"id":"T1211","name":"Exploitation for Defense Evasion","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Employing diverse security tool implementations and trust validation mechanisms across the environment limits an adversary's ability to use a single defense evasion exploit universally, as each technology stack presents different attack surfaces."}],"metadata":{"last_reviewed":"2026-02-13","review_notes":"","mapping_status":"pending"},"function":"preventative","used_by_patterns":[]}}