{"data":{"id":"SC-34","name":"Non-modifiable Executable Programs","family":"SC","family_name":"System and Communications Protection","withdrawn":false,"description":"For [Assignment: organization-defined system components], load and execute:\na. The operating environment from hardware-enforced, read-only media; and\nb. The following applications from hardware-enforced, read-only media: [Assignment: organization-defined applications].","supplemental_guidance":"The operating environment for a system contains the code that hosts applications, including operating systems, executives, or virtual machine monitors (i.e., hypervisors). It can also include certain applications that run directly on hardware platforms. Hardware-enforced, read-only media include Compact Disc-Recordable (CD-R) and Digital Versatile Disc-Recordable (DVD-R) disk drives as well as one-time, programmable, read-only memory. The use of non-modifiable storage ensures the integrity of software from the point of creation of the read-only image. The use of reprogrammable, read-only memory can be accepted as read-only media provided that integrity can be adequately protected from the point of initial writing to the insertion of the memory into the system, and there are reliable hardware protections against reprogramming the memory while installed in organizational systems.","enhancements":[{"id":"SC-34(01)","name":"No Writable Storage","statement":"Employ [Assignment: organization-defined system components] with no writeable storage that is persistent across component restart or power on/off.","baselines":[]},{"id":"SC-34(02)","name":"Integrity Protection on Read-only Media","statement":"Protect the integrity of information prior to storage on read-only media and control the media after such information has been recorded onto the media.","baselines":[]},{"id":"SC-34(03)","name":"Hardware-based Protection","withdrawn":true,"incorporated_into":["SC-51"]}],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"nist_800_53":{"rev5":{"id":"SC-34","name":"Non-modifiable Executable Programs","description":"For [Assignment: organization-defined system components], load and execute:\na. The operating environment from hardware-enforced, read-only media; and\nb. The following applications from hardware-enforced, read-only media: [Assignment: organization-defined applications].","discussion":"The operating environment for a system contains the code that hosts applications, including operating systems, executives, or virtual machine monitors (i.e., hypervisors). It can also include certain applications that run directly on hardware platforms. Hardware-enforced, read-only media include Compact Disc-Recordable (CD-R) and Digital Versatile Disc-Recordable (DVD-R) disk drives as well as one-time, programmable, read-only memory. The use of non-modifiable storage ensures the integrity of software from the point of creation of the read-only image. The use of reprogrammable, read-only memory can be accepted as read-only media provided that integrity can be adequately protected from the point of initial writing to the insertion of the memory into the system, and there are reliable hardware protections against reprogramming the memory while installed in organizational systems.","related_controls":["AC-03","SI-07","SI-14"],"baseline_low":null,"baseline_moderate":null,"baseline_high":null,"baseline_privacy":null,"new_in_rev5":false,"changes_from_rev4":"No significant title changes from Rev 4."}},"compliance_mappings":{"iso_27001_2022":[],"iso_27002_2022":[],"cobit_2019":[],"pci_dss_v4":["5.2"],"nist_csf_2":["DE.CM-09","PR.PS-05"],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":[],"osfi_b13":[],"finma_circular":["IV.C(64)","IV.D(72)"],"gdpr":[],"dora":[],"bio2":[],"rbi_csf":["Annex1.5"],"fisc":["FISC.T7"],"lgpd_bcb":[],"hkma_tme1":[],"mlps_2":[],"dnb_good_practice":[],"cra":["CRA.I.2k"],"swift_cscf":[],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":["B"],"fips_140":["FIPS 140-3 §7.5"],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":["SA-3"],"hitrust_csf":[],"iso_27799":[],"lloyds_ms":[],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1542","name":"Pre-OS Boot","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Loading the operating environment from hardware-enforced read-only media prevents adversaries from modifying pre-OS boot components, as the boot chain is physically immutable and cannot be altered to establish persistence below the operating system."},{"id":"T1548","name":"Abuse Elevation Control Mechanism","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Non-modifiable executable programs loaded from read-only media prevent adversaries from altering elevation control mechanisms, as the binaries responsible for privilege management cannot be tampered with to bypass authorization checks."},{"id":"T1553","name":"Subvert Trust Controls","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Hardware-enforced read-only execution environments prevent adversaries from subverting trust controls by modifying signed binaries or trust validation logic, as the code integrity verification chain itself resides on immutable media."},{"id":"T1601","name":"Modify System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Executing system images from non-modifiable, hardware-enforced read-only media directly prevents adversaries from patching or replacing the running system image, as physical write protection makes persistent modification impossible."},{"id":"T1611","name":"Escape to Host","tactics":["privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Non-modifiable executable environments loaded from read-only media limit container escape techniques by ensuring that host operating system binaries and kernel components cannot be modified even if an adversary gains write access within a container."},{"id":"T1195.003","name":"Compromise Hardware Supply Chain","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Hardware-enforced read-only boot media provides a trusted execution baseline that detects or resists compromised hardware supply chain components, as the expected system image is immutable and any discrepancy with hardware behavior becomes evident."},{"id":"T1218.015","name":"Electron Applications","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Loading applications from hardware-enforced read-only media prevents adversaries from modifying Electron application binaries to proxy malicious execution, as the application code and its embedded runtime are physically protected from tampering."},{"id":"T1542.001","name":"System Firmware","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Non-modifiable boot media prevents adversaries from installing persistent system firmware modifications, as the UEFI/BIOS image is loaded from hardware-enforced read-only storage that cannot be reflashed through software-based attacks."},{"id":"T1542.003","name":"Bootkit","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Hardware-enforced read-only boot media directly prevents bootkit installation by making the master boot record and boot partition physically immutable, blocking adversary attempts to establish pre-OS persistence through boot sector modification."},{"id":"T1542.004","name":"ROMMONkit","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Executing network device firmware from non-modifiable media prevents ROMMONkit installation by ensuring the bootstrap monitor program resides on hardware-enforced read-only storage that cannot be altered by adversary-injected code."},{"id":"T1542.005","name":"TFTP Boot","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Non-modifiable boot media eliminates TFTP boot manipulation by ensuring devices boot exclusively from local read-only storage rather than network-provided images, preventing adversaries from substituting malicious boot images via compromised TFTP servers."},{"id":"T1548.004","name":"Elevated Execution with Prompt","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Loading system binaries from read-only media ensures that authorization prompt mechanisms cannot be tampered with to auto-approve elevation requests, as the executables governing privilege escalation prompts are physically write-protected."},{"id":"T1553.006","name":"Code Signing Policy Modification","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Hardware-enforced read-only execution prevents adversaries from modifying code signing policies stored on the boot media, as the signing enforcement configuration is immutable and cannot be weakened through software-based policy changes."},{"id":"T1601.001","name":"Patch System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Non-modifiable executable media directly prevents adversaries from patching network device system images, as the firmware resides on hardware-enforced read-only storage where in-place modifications are physically impossible."},{"id":"T1601.002","name":"Downgrade System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Hardware-enforced read-only media prevents adversaries from downgrading system images to vulnerable versions, as the current firmware is physically protected from replacement and the boot process loads only from the immutable source."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: nist_csf_2 DE.CM-09, PR.PS-05 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"preventative","used_by_patterns":[]}}