{"data":{"id":"SC-36","name":"Distributed Processing and Storage","family":"SC","family_name":"System and Communications Protection","withdrawn":false,"description":"Distribute the following processing and storage components across multiple [Selection (one): physical locations; logical domains]: [Assignment: organization-defined processing and storage components].","supplemental_guidance":"Distributing processing and storage across multiple physical locations or logical domains provides a degree of redundancy or overlap for organizations. The redundancy and overlap increase the work factor of adversaries to adversely impact organizational operations, assets, and individuals. The use of distributed processing and storage does not assume a single primary processing or storage location. Therefore, it allows for parallel processing and storage.","enhancements":[{"id":"SC-36(01)","name":"Polling Techniques","statement":"a. Employ polling techniques to identify potential faults, errors, or compromises to the following processing and storage components: [Assignment: organization-defined distributed processing and storage components]; and\nb. Take the following actions in response to identified faults, errors, or compromises: [Assignment: organization-defined actions].","baselines":[]},{"id":"SC-36(02)","name":"Synchronization","statement":"Synchronize the following duplicate systems or system components: [Assignment: organization-defined duplicate systems or system components].","baselines":[]}],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"nist_800_53":{"rev5":{"id":"SC-36","name":"Distributed Processing and Storage","description":"Distribute the following processing and storage components across multiple [Selection (one): physical locations; logical domains]: [Assignment: organization-defined processing and storage components].","discussion":"Distributing processing and storage across multiple physical locations or logical domains provides a degree of redundancy or overlap for organizations. The redundancy and overlap increase the work factor of adversaries to adversely impact organizational operations, assets, and individuals. The use of distributed processing and storage does not assume a single primary processing or storage location. Therefore, it allows for parallel processing and storage.","related_controls":["CP-06","CP-07","PL-08","SC-32"],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"No significant changes from Rev 4."}},"compliance_mappings":{"iso_27001_2022":[],"iso_27002_2022":["8.14"],"cobit_2019":[],"pci_dss_v4":[],"nist_csf_2":["PR.IR-03"],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":[],"osfi_b13":[],"finma_circular":[],"gdpr":[],"dora":[],"bio2":["8.14"],"rbi_csf":["ITGRCA.29"],"fisc":[],"lgpd_bcb":[],"hkma_tme1":[],"mlps_2":[],"dnb_good_practice":[],"cra":[],"swift_cscf":[],"qatar_nia":["CS"],"cpmi_pfmi":["CG.RR"],"ecb_croe":["CROE.2.5.2"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":["SYSC 13.8.2"],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":[],"iso_27799":["17.3"],"lloyds_ms":[],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1070","name":"Indicator Removal","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Distributed processing and storage ensures that log data exists across multiple locations, making indicator removal ineffective because adversaries cannot delete all copies of forensic evidence from geographically or logically distributed storage."},{"id":"T1119","name":"Automated Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Distribution of data across multiple locations complicates automated collection by requiring adversaries to discover and access multiple storage points, increasing the complexity and detection surface of data-harvesting operations."},{"id":"T1565","name":"Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Distributed storage with redundancy enables detection of data manipulation by maintaining multiple copies of critical data across separate locations, allowing integrity verification through cross-copy comparison."},{"id":"T1070.001","name":"Clear Windows Event Logs","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Distributed log storage ensures Windows Event Log data is replicated to remote collectors, making local log-clearing ineffective because centralized copies of security events survive endpoint-level deletion."},{"id":"T1070.002","name":"Clear Linux or Mac System Logs","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Distributed processing ensures Unix/Mac system logs are forwarded to remote syslog servers, preserving forensic evidence even when adversaries clear local log files on compromised systems."},{"id":"T1070.008","name":"Clear Mailbox Data","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Distributed email storage ensures mailbox data exists in multiple locations, making local mailbox-data clearing ineffective because replicated copies of email content survive adversary deletion attempts."},{"id":"T1565.001","name":"Stored Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Distributed storage with integrity verification enables detection of stored-data manipulation by maintaining multiple data copies across separate locations, identifying modifications through cross-site consistency checks."}],"metadata":{"last_reviewed":"2026-02-19","review_notes":"Generated from NIST SP 800-53 Rev 5 with compliance mappings from framework-coverage data","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-034"]}}