{"data":{"id":"SC-30","name":"Concealment and Misdirection","family":"SC","family_name":"System and Communications Protection","withdrawn":false,"description":"Employ the following concealment and misdirection techniques for [Assignment: organization-defined systems] at [Assignment: organization-defined time periods] to confuse and mislead adversaries: [Assignment: organization-defined concealment and misdirection techniques].","supplemental_guidance":"Concealment and misdirection techniques can significantly reduce the targeting capabilities of adversaries (i.e., window of opportunity and available attack surface) to initiate and complete attacks. For example, virtualization techniques provide organizations with the ability to disguise systems, potentially reducing the likelihood of successful attacks without the cost of having multiple platforms. The increased use of concealment and misdirection techniques and methods—including randomness, uncertainty, and virtualization—may sufficiently confuse and mislead adversaries and subsequently increase the risk of discovery and/or exposing tradecraft. Concealment and misdirection techniques may provide additional time to perform core mission and business functions. The implementation of concealment and misdirection techniques may add to the complexity and management overhead required for the system.","enhancements":[{"id":"SC-30(01)","name":"Virtualization Techniques","withdrawn":true,"incorporated_into":["SC-29(01)"]},{"id":"SC-30(02)","name":"Randomness","statement":"Employ [Assignment: organization-defined techniques] to introduce randomness into organizational operations and assets.","baselines":[]},{"id":"SC-30(03)","name":"Change Processing and Storage Locations","statement":"Change the location of [Assignment: organization-defined processing and/or storage] [Selection (one): [Assignment: organization-defined time frequency]; at random time intervals].","baselines":[]},{"id":"SC-30(04)","name":"Misleading Information","statement":"Employ realistic, but misleading information in [Assignment: organization-defined system components] about its security state or posture.","baselines":[]},{"id":"SC-30(05)","name":"Concealment of System Components","statement":"Employ the following techniques to hide or conceal [Assignment: organization-defined system components]: [Assignment: organization-defined techniques].","baselines":[]}],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"nist_800_53":{"rev5":{"id":"SC-30","name":"Concealment and Misdirection","description":"Employ the following concealment and misdirection techniques for [Assignment: organization-defined systems] at [Assignment: organization-defined time periods] to confuse and mislead adversaries: [Assignment: organization-defined concealment and misdirection techniques].","discussion":"Concealment and misdirection techniques can significantly reduce the targeting capabilities of adversaries (i.e., window of opportunity and available attack surface) to initiate and complete attacks. For example, virtualization techniques provide organizations with the ability to disguise systems, potentially reducing the likelihood of successful attacks without the cost of having multiple platforms. The increased use of concealment and misdirection techniques and methods—including randomness, uncertainty, and virtualization—may sufficiently confuse and mislead adversaries and subsequently increase the risk of discovery and/or exposing tradecraft. Concealment and misdirection techniques may provide additional time to perform core mission and business functions. The implementation of concealment and misdirection techniques may add to the complexity and management overhead required for the system.","related_controls":["AC-06","SC-25","SC-26","SC-29","SC-44","SI-14"],"baseline_low":null,"baseline_moderate":null,"baseline_high":null,"baseline_privacy":null,"new_in_rev5":false,"changes_from_rev4":"No significant title changes from Rev 4."}},"compliance_mappings":{"iso_27001_2022":[],"iso_27002_2022":[],"cobit_2019":[],"pci_dss_v4":[],"nist_csf_2":[],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":[],"osfi_b13":[],"finma_circular":[],"gdpr":[],"dora":[],"bio2":[],"rbi_csf":["Annex1.4"],"fisc":[],"lgpd_bcb":[],"hkma_tme1":[],"mlps_2":[],"dnb_good_practice":[],"cra":["CRA.I.2k"],"swift_cscf":[],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":[],"iso_27799":[],"lloyds_ms":[],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1068","name":"Exploitation for Privilege Escalation","tactics":["privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Concealment techniques including ASLR, memory layout randomization, and system virtualization increase the difficulty and unreliability of privilege escalation exploits by creating unpredictable execution environments."},{"id":"T1189","name":"Drive-by Compromise","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Deploying honeypot web infrastructure and randomized system configurations misleads adversaries conducting drive-by compromise reconnaissance, directing attacks toward decoy systems rather than production assets."},{"id":"T1190","name":"Exploit Public-Facing Application","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Concealment and misdirection through application-layer deception, including fake services and honeypots, diverts exploitation attempts against public-facing applications toward monitored decoy systems."},{"id":"T1203","name":"Exploitation for Client Execution","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Randomized memory layouts, dynamic system configurations, and virtualization-based isolation increase the unreliability of client-side exploitation, as exploit payloads encounter unpredictable execution environments."},{"id":"T1210","name":"Exploitation of Remote Services","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Network-level misdirection through honeypots and fake services attracts and identifies lateral movement exploitation attempts, diverting adversary attention from actual vulnerable services to monitored decoys."},{"id":"T1211","name":"Exploitation for Defense Evasion","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Concealment techniques such as ASLR and Control Flow Integrity randomize the execution environment, making defense evasion exploits unreliable as memory layouts and code paths are unpredictable."},{"id":"T1212","name":"Exploitation for Credential Access","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Misdirection through credential-bearing honeypots and deception technologies attracts credential access exploitation attempts toward monitored decoy systems, enabling early detection of adversary activity."}],"metadata":{"last_reviewed":"2026-02-13","review_notes":"","mapping_status":"pending"},"function":"preventative","used_by_patterns":[]}}