{"data":{"id":"SI-02","name":"Flaw Remediation","family":"SI","family_name":"System and Information Integrity","withdrawn":false,"description":"a. Identify, report, and correct system flaws;\nb. Test software and firmware updates related to flaw remediation for effectiveness and potential side effects before installation;\nc. Install security-relevant software and firmware updates within [Assignment: organization-defined time period] of the release of the updates; and\nd. Incorporate flaw remediation into the organizational configuration management process.","supplemental_guidance":"The need to remediate system flaws applies to all types of software and firmware. Organizations identify systems affected by software flaws, including potential vulnerabilities resulting from those flaws, and report this information to designated organizational personnel with information security and privacy responsibilities. Organizations consider establishing a controlled patching environment for mission-critical systems. Security-relevant updates include patches, service packs, and malicious code signatures. Organizations also address flaws discovered during assessments, continuous monitoring, incident response activities, and system error handling. By incorporating flaw remediation into configuration management processes, required remediation actions can be tracked and verified.\n\nOrganization-defined time periods for updating security-relevant software and firmware may vary based on a variety of risk factors, including the security category of the system, the criticality of the update (i.e., severity of the vulnerability related to the discovered flaw), the organizational risk tolerance, the mission supported by the system, or the threat environment. Some types of flaw remediation may require more testing than other types. Organizations determine the type of testing needed for the specific type of flaw remediation activity under consideration and the types of changes that are to be configuration-managed. Flaw remediation testing analyzes both the effectiveness of addressing security issues and any potential side-effects on functionality, system and system component performance, and operations. When implementing remediation activities, organizations consider the order and timing of updates to validate correct execution within the system environment and to support system and component availability needs (i.e., implementing a staggered deployment strategy). Organizations verify that software and firmware updates come from authorized sources prior to downloading.In testing decisions, organizations consider whether security-relevant software or firmware updates are obtained from authorized sources with appropriate digital signatures.","enhancements":[{"id":"SI-02(01)","name":"Central Management","withdrawn":true,"incorporated_into":["PL-09"]},{"id":"SI-02(02)","name":"Automated Flaw Remediation Status","statement":"Determine if system components have applicable security-relevant software and firmware updates installed using [Assignment: organization-defined automated mechanisms] [Assignment: organization-defined frequency].","baselines":["moderate","high"]},{"id":"SI-02(03)","name":"Time to Remediate Flaws and Benchmarks for Corrective Actions","statement":"a. Measure the time between flaw identification and flaw remediation; and\nb. Establish the following benchmarks for taking corrective actions: [Assignment: organization-defined benchmarks].","baselines":[]},{"id":"SI-02(04)","name":"Automated Patch Management Tools","statement":"Employ automated patch management tools to facilitate flaw remediation to the following system components: [Assignment: organization-defined system components].","baselines":[]},{"id":"SI-02(05)","name":"Automatic Software and Firmware Updates","statement":"Install [Assignment: organization-defined security-relevant software and firmware updates] automatically to [Assignment: organization-defined system components].","baselines":[]},{"id":"SI-02(06)","name":"Removal of Previous Versions of Software and Firmware","statement":"Remove previous versions of [Assignment: organization-defined software and firmware components] after updated versions have been installed.","baselines":[]},{"id":"SI-02(07)","name":"Root Cause Analysis","statement":"a. Conduct root cause analysis to identify the underlying causes of issues or failures;\nb. Develop actions to address the root cause of the issue or failure;\nc. Implement the actions and monitor the implementation for effectiveness.","baselines":[]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"SI-02","name":"Flaw Remediation","description":"a. Identify, report, and correct system flaws;\nb. Test software and firmware updates related to flaw remediation for effectiveness and potential side effects before installation;\nc. Install security-relevant software and firmware updates within [Assignment: organization-defined time period] of the release of the updates; and\nd. Incorporate flaw remediation into the organizational configuration management process.","discussion":"The need to remediate system flaws applies to all types of software and firmware. Organizations identify systems affected by software flaws, including potential vulnerabilities resulting from those flaws, and report this information to designated organizational personnel with information security and privacy responsibilities. Organizations consider establishing a controlled patching environment for mission-critical systems. Security-relevant updates include patches, service packs, and malicious code signatures. Organizations also address flaws discovered during assessments, continuous monitoring, incident response activities, and system error handling. By incorporating flaw remediation into configuration management processes, required remediation actions can be tracked and verified.\n\nOrganization-defined time periods for updating security-relevant software and firmware may vary based on a variety of risk factors, including the security category of the system, the criticality of the update (i.e., severity of the vulnerability related to the discovered flaw), the organizational risk tolerance, the mission supported by the system, or the threat environment. Some types of flaw remediation may require more testing than other types. Organizations determine the type of testing needed for the specific type of flaw remediation activity under consideration and the types of changes that are to be configuration-managed. Flaw remediation testing analyzes both the effectiveness of addressing security issues and any potential side-effects on functionality, system and system component performance, and operations. When implementing remediation activities, organizations consider the order and timing of updates to validate correct execution within the system environment and to support system and component availability needs (i.e., implementing a staggered deployment strategy). Organizations verify that software and firmware updates come from authorized sources prior to downloading.In testing decisions, organizations consider whether security-relevant software or firmware updates are obtained from authorized sources with appropriate digital signatures.","related_controls":["CA-05","CM-03","CM-04","CM-05","CM-06","CM-08","MA-02","RA-05","SA-08","SA-10","SA-11","SI-03","SI-05","SI-07","SI-11"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":""}},"compliance_mappings":{"iso_27001_2022":["A.6.8","A.8.8","A.8.32"],"iso_27002_2022":["8.8"],"cobit_2019":["DSS03"],"pci_dss_v4":["6.3","6.3.3","11.3"],"nist_csf_2":["ID.IM-01","ID.IM-02","ID.IM-03","ID.RA-01","ID.RA-08","PR.PS-02"],"cis_controls_v8":["CIS 7","CIS 7.1","CIS 7.2","CIS 7.3","CIS 7.4","CIS 7.7","CIS 12.1","CIS 14.7","CIS 16.2","CIS 18.3"],"soc2_tsc":["CC9.2-POF13"],"finos_ccc":["CCC-C10"],"iso_42001_2023":["A.6.2.6"],"iec_62443":[],"asd_e8":["E8-2","E8-2 ML1","E8-2 ML2","E8-2 ML3","E8-6","E8-6 ML1","E8-6 ML2","E8-6 ML3"],"nis2":["Art. 21(2)(e)","Art. 21(2)(g)"],"apra_cps_234":["Para 19-20","Para 22-23"],"mas_trm":["7"],"pra_op_resilience":[],"bsi_grundschutz":["OPS.1.1.3","SYS.1.1","SYS.2.1"],"anssi":["Hygiene.18","Hygiene.33","Hygiene.34","SecNumCloud.13.6"],"osfi_b13":["B-13.2.4"],"finma_circular":["IV.A(36)","IV.B.c(56)","IV.B.d(59)","IV.C(64)"],"gdpr":["Art.32(1)(b)","Art.32(1)(d)"],"dora":["Art.7(2)","Art.9(4)(e)"],"bio2":["8.8"],"rbi_csf":["Annex1.7","ITGRCA.13"],"fisc":["FISC.O12","FISC.T7"],"lgpd_bcb":["BCB.Art.3","BCB.Art.6","LGPD.Art.46"],"hkma_tme1":["TME1.5.4","TME1.7.4"],"mlps_2":["8.1.4.4","8.1.10.3","8.1.10.4"],"dnb_good_practice":["DNB.19.2"],"cra":["CRA.I.2a","CRA.I.2c","CRA.II.2","CRA.II.7","CRA.II.8","CRA.Info.8c"],"swift_cscf":["SWIFT.2.2","SWIFT.2.7"],"cbb_tm":["TM-5","TM-11"],"cbuae":["CR-7"],"nca_ecc":["2-3","2-10"],"qatar_nia":["OS"],"sama_csf":["3.5"],"uae_ia":["T7"],"bog_cisd":["CISD-VI"],"bom_ctrm":["3.6"],"cbe_csf":["CTO-9"],"cbn_csf":["Part2.3","Part3.3"],"popia":["s19"],"sa_js2":["JS2-7.2","JS2-8.5"],"bot_cyber":["Ch3.2","Ch10.1"],"cpmi_pfmi":["CG.LE","CG.PR","PFMI.P17"],"eba_ict":["3.4.4","3.5(b)"],"ecb_croe":["CROE.2.3.4","CROE.2.8.1","CROE.2.8.2"],"ffiec_is":["II.A.2","II.C.11"],"iosco_cyber":["PROT-6","SA-3"],"nydfs_500":["500.5","500.8"],"sebi_cscrf":["PR.IP"],"cmmc_2":["SI"],"nerc_cip":["CIP-007-6"],"nrc_73_54":["RG5.71-A-SI"],"tsa_psd":["SD-2 Sec D"],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":["THREAT"],"api_1164":["Sec 7"],"awia":[],"iaea_nss":["Sec 5.4"],"pci_pts":["F"],"fips_140":["FIPS 140-3 §7.12"],"cbest":["CBEST.6"],"tiber_eu":["TIBER.REM"],"pci_hsm":[],"common_criteria":[],"isae_3402":["Clause 4"],"fca_sysc_13":["SYSC 13.7.1","SYSC 13.7.2","SYSC 13.7.4"],"fda_21_cfr_11":[],"fda_cyber":["524B-2","MON-2","PU-1","PU-2","PU-3","SBOM-2","SBOM-3","VR-2"],"hitrust_csf":["09.c","10.e"],"iso_27799":["12.5","18.4","H.3"],"lloyds_ms":["MS8.4","MS8.11"],"naic_ds":["4B"],"nhs_dspt":["NDG-8.1","NDG-8.2","NDG-9.9"],"pra_ss1_23":[],"solvency_ii":["DR.266","EIOPA-ICT-4.8"],"owasp_masvs_v2":["MASVS-CODE-1","MASVS-CODE-2","MASVS-CODE-3"],"csa_ccm_v4":["AIS-07","IVS-04","TVM-03","TVM-04","UEM-07"],"csa_aicm":["I&S-04","TVM-03","TVM-04","UEM-07"],"ccss_v9":["2.01.1"],"mica":["Art.62(5)"],"basel_sco60":["SCO60.51","SCO60.65"],"bssc":["GSP-08","NOS-03","NOS-10"],"sec_custody_digital":["SEC-CD-07"],"dpdpa":["Act.8(5)","Rules.Sch1.B.7"]},"attack_techniques":[{"id":"T1003","name":"OS Credential Dumping","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Timely patching of operating system credential protection mechanisms closes vulnerabilities that adversaries exploit to bypass security controls and dump credentials from protected stores."},{"id":"T1027","name":"Obfuscated Files or Information","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Patching file parsing and deobfuscation engines ensures that security tools can properly analyze obfuscated payloads, closing detection gaps that adversaries exploit with packed or encoded malware."},{"id":"T1047","name":"Windows Management Instrumentation","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Patching WMI implementation vulnerabilities eliminates the flaws that adversaries exploit to achieve remote code execution or privilege escalation through Windows Management Instrumentation."},{"id":"T1055","name":"Process Injection","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Applying security patches to process isolation mechanisms closes the memory management vulnerabilities that adversaries exploit for cross-process code injection and privilege escalation."},{"id":"T1059","name":"Command and Scripting Interpreter","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Patching scripting engine vulnerabilities eliminates code execution flaws in PowerShell, VBScript, and other interpreters that adversaries exploit for initial payload execution and lateral movement."},{"id":"T1068","name":"Exploitation for Privilege Escalation","tactics":["privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Prompt application of kernel and system patches directly eliminates the specific software vulnerabilities that adversaries exploit to escalate from user-level to system-level privileges."},{"id":"T1072","name":"Software Deployment Tools","tactics":["execution","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Patching software deployment tool vulnerabilities prevents adversaries from exploiting flaws in SCCM, Ansible, and similar platforms to gain trusted code execution across managed endpoints."},{"id":"T1106","name":"Native API","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Applying OS patches that harden native API implementations closes the low-level vulnerabilities that adversaries exploit when invoking system calls for process manipulation and privilege escalation."},{"id":"T1137","name":"Office Application Startup","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Patching Office application vulnerabilities eliminates the flaws that adversaries exploit to achieve persistent code execution through modified templates, macros, and add-ins."},{"id":"T1189","name":"Drive-by Compromise","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Patching browser and plugin vulnerabilities directly eliminates the exploitation vectors that adversaries target in drive-by compromise attacks delivered through compromised or malicious websites."},{"id":"T1190","name":"Exploit Public-Facing Application","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Prompt remediation of public-facing application vulnerabilities closes the specific flaws that adversaries scan for and exploit to gain initial access to internet-exposed services."},{"id":"T1195","name":"Supply Chain Compromise","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Applying vendor patches to compromised software removes supply chain-injected malicious code, and keeping dependencies current reduces the window of exposure to known supply chain vulnerabilities."},{"id":"T1203","name":"Exploitation for Client Execution","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Patching client application vulnerabilities eliminates the specific memory corruption and logic flaws that adversaries weaponize in documents and files for client-side code execution."},{"id":"T1204","name":"User Execution","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Keeping applications patched reduces the exploitable attack surface that adversaries leverage when tricking users into opening malicious files or links for code execution."},{"id":"T1210","name":"Exploitation of Remote Services","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Patching remote service vulnerabilities eliminates the specific flaws in SMB, RDP, SSH, and other network services that adversaries exploit for lateral movement across the network."},{"id":"T1211","name":"Exploitation for Defense Evasion","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Remediating vulnerabilities in security tools and defense components prevents adversaries from exploiting flaws to disable, bypass, or evade detection and protection mechanisms."},{"id":"T1212","name":"Exploitation for Credential Access","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Patching authentication service vulnerabilities closes the flaws that adversaries exploit to extract, intercept, or forge credentials through authentication protocol weaknesses."},{"id":"T1221","name":"Template Injection","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Patching Office template injection vulnerabilities prevents adversaries from using document templates to load malicious remote resources for payload delivery and execution."},{"id":"T1495","name":"Firmware Corruption","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Applying firmware patches closes the vulnerabilities that adversaries exploit to corrupt or modify device firmware, and ensures firmware integrity verification mechanisms function correctly."},{"id":"T1525","name":"Implant Internal Image","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Patching container runtime and registry vulnerabilities prevents adversaries from exploiting flaws to inject malicious images or modify running containers for persistent execution."},{"id":"T1542","name":"Pre-OS Boot","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Applying firmware and bootloader patches eliminates vulnerabilities in pre-OS boot components that adversaries exploit to install persistent rootkits below the operating system."},{"id":"T1546","name":"Event Triggered Execution","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Patching event handler and callback vulnerabilities closes the flaws that adversaries exploit to register malicious event-triggered execution hooks for persistent code execution."},{"id":"T1548","name":"Abuse Elevation Control Mechanism","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Patching privilege elevation mechanisms (sudo, UAC, setuid) eliminates the specific bypass vulnerabilities that adversaries exploit to circumvent intended privilege boundaries."},{"id":"T1552","name":"Unsecured Credentials","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Remediating credential storage vulnerabilities ensures that credentials are properly protected, closing flaws that expose passwords, keys, and tokens in accessible locations."},{"id":"T1553","name":"Subvert Trust Controls","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Patching code signing and certificate validation vulnerabilities prevents adversaries from exploiting trust control weaknesses to execute unsigned or improperly-verified malicious code."},{"id":"T1555","name":"Credentials from Password Stores","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Patching password manager and credential store vulnerabilities closes the flaws that adversaries exploit to extract stored credentials from browser password stores and keychain applications."},{"id":"T1559","name":"Inter-Process Communication","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Patching COM and DDE implementation vulnerabilities eliminates the inter-process communication flaws that adversaries exploit for cross-application code execution."},{"id":"T1566","name":"Phishing","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Patching email client and document rendering vulnerabilities reduces the exploitation surface that adversaries leverage in phishing attacks to achieve code execution from malicious attachments."},{"id":"T1574","name":"Hijack Execution Flow","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Patching DLL loading and path resolution vulnerabilities eliminates the specific implementation flaws that adversaries exploit to hijack legitimate execution flows for code injection."},{"id":"T1601","name":"Modify System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Applying firmware patches to network devices closes the vulnerabilities that adversaries exploit to modify system images, and updating to current firmware eliminates known backdoor vectors."},{"id":"T1606","name":"Forge Web Credentials","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Patching web credential generation and validation vulnerabilities prevents adversaries from exploiting flaws in token signing, cookie handling, or SAML processing to forge authentication material."},{"id":"T1611","name":"Escape to Host","tactics":["privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Patching container runtime isolation vulnerabilities closes the specific escape vectors that adversaries exploit to break out of container boundaries and access the host system."},{"id":"T1003.001","name":"LSASS Memory","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Patching LSASS vulnerabilities and enabling Credential Guard closes the specific memory protection weaknesses that adversaries exploit with tools like Mimikatz to dump LSASS credentials."},{"id":"T1027.002","name":"Software Packing","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Keeping antimalware engines patched ensures current unpacking capabilities that detect packed malware, closing evasion gaps that adversaries exploit with software packing obfuscation."},{"id":"T1027.007","name":"Dynamic API Resolution","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Patching API hooking and monitoring mechanisms ensures security tools can detect dynamic API resolution techniques that adversaries use to evade static import table analysis."},{"id":"T1027.008","name":"Stripped Payloads","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Keeping content inspection engines patched ensures they can detect stripped payloads where adversaries have removed identifying information to evade signature-based detection."},{"id":"T1027.009","name":"Embedded Payloads","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Patching file parsing and analysis engines ensures security tools can properly detect embedded payloads concealed within carrier files."},{"id":"T1055.001","name":"Dynamic-link Library Injection","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Patching DLL loading vulnerabilities and process isolation mechanisms prevents adversaries from exploiting specific flaws for dynamic-link library injection into legitimate processes."},{"id":"T1055.002","name":"Portable Executable Injection","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Applying patches that strengthen process memory protection prevents adversaries from exploiting memory management flaws for portable executable injection into running processes."},{"id":"T1055.003","name":"Thread Execution Hijacking","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Patching thread management APIs closes vulnerabilities that adversaries exploit to hijack execution threads in legitimate processes for code injection."},{"id":"T1055.004","name":"Asynchronous Procedure Call","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Applying patches to APC dispatch mechanisms closes the vulnerabilities that adversaries exploit to queue malicious asynchronous procedure calls in target processes."},{"id":"T1055.005","name":"Thread Local Storage","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Patching TLS callback handling eliminates the thread local storage vulnerabilities that adversaries exploit to redirect execution to injected code during DLL loading."},{"id":"T1055.008","name":"Ptrace System Calls","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Patching kernel ptrace implementation hardens process debugging interfaces, closing the vulnerabilities that adversaries exploit for process attachment and code injection on Linux."},{"id":"T1055.009","name":"Proc Memory","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Applying patches that restrict /proc memory access closes the vulnerabilities that adversaries exploit to directly read and write process memory for code injection."},{"id":"T1055.011","name":"Extra Window Memory Injection","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Patching window management APIs closes the extra window memory vulnerabilities that adversaries exploit to inject code through GUI subsystem interfaces."},{"id":"T1055.012","name":"Process Hollowing","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Applying patches to process creation and memory management closes the vulnerabilities that adversaries exploit to hollow out legitimate processes and replace their code."},{"id":"T1055.013","name":"Process Doppelgänging","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Patching NTFS transactional file system APIs closes the vulnerabilities that adversaries exploit for process doppelganging code injection through transactional file operations."},{"id":"T1055.014","name":"VDSO Hijacking","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Patching VDSO mapping mechanisms closes the kernel-user space interface vulnerabilities that adversaries exploit for VDSO hijacking on Linux systems."},{"id":"T1059.001","name":"PowerShell","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Patching PowerShell engine vulnerabilities and enforcing current versions eliminates the specific execution bypass flaws that adversaries exploit in older PowerShell versions."},{"id":"T1059.005","name":"Visual Basic","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Patching VBScript and VBA engine vulnerabilities eliminates code execution flaws that adversaries exploit through malicious macros and Visual Basic scripts."},{"id":"T1059.006","name":"Python","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Patching Python interpreter vulnerabilities and keeping runtime versions current closes the code execution flaws that adversaries exploit through Python-based post-exploitation tooling."},{"id":"T1137.003","name":"Outlook Forms","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Patching Exchange and Outlook form handling vulnerabilities prevents adversaries from exploiting custom form rendering flaws to achieve code execution through malicious Outlook Forms."},{"id":"T1137.004","name":"Outlook Home Page","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Patching Outlook folder home page rendering vulnerabilities eliminates the flaws that adversaries exploit to load and execute malicious content through custom home page URLs."},{"id":"T1137.005","name":"Outlook Rules","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Patching Outlook rule processing vulnerabilities prevents adversaries from exploiting rule engine flaws to execute arbitrary commands or scripts triggered by incoming email rules."},{"id":"T1195.001","name":"Compromise Software Dependencies and Development Tools","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Patching and continuously scanning software dependencies eliminates known vulnerabilities in third-party libraries and development tools that adversaries compromise in supply chain attacks."},{"id":"T1195.002","name":"Compromise Software Supply Chain","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Patching software update mechanisms and verifying update integrity prevents adversaries from exploiting compromised software distribution channels to deliver malicious payloads."},{"id":"T1195.003","name":"Compromise Hardware Supply Chain","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Applying firmware updates to hardware components and validating hardware integrity addresses supply chain compromises where adversaries tamper with hardware before or during delivery."},{"id":"T1204.001","name":"Malicious Link","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Patching URL handling and link processing vulnerabilities in browsers and email clients reduces the exploitation surface when users click adversary-crafted malicious links."},{"id":"T1204.003","name":"Malicious Image","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Patching container runtime vulnerabilities ensures that malicious container images cannot exploit known flaws in the image parsing and execution pipeline to achieve host-level access."},{"id":"T1213.003","name":"Code Repositories","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Patching code repository platform vulnerabilities (GitLab, GitHub Enterprise, Bitbucket) closes the access control and authentication flaws that adversaries exploit to access source code."},{"id":"T1213.005","name":"Messaging Applications","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Patching messaging platform vulnerabilities closes the API and authentication flaws that adversaries exploit to access and exfiltrate data from Slack, Teams, and similar applications."},{"id":"T1542.001","name":"System Firmware","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Applying UEFI firmware patches closes the specific vulnerabilities that adversaries exploit to implant persistent code in system firmware that executes before the operating system loads."},{"id":"T1542.003","name":"Bootkit","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Patching bootloader vulnerabilities and enforcing Secure Boot eliminates the boot-level flaws that adversaries exploit to install bootkits in the Master Boot Record."},{"id":"T1542.004","name":"ROMMONkit","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Applying firmware updates to network device ROMMON eliminates the known vulnerabilities that adversaries exploit to install persistent implants in router ROM Monitor firmware."},{"id":"T1542.005","name":"TFTP Boot","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Patching TFTP implementation and boot configuration vulnerabilities prevents adversaries from exploiting network boot flaws to redirect devices to load compromised operating system images."},{"id":"T1546.006","name":"LC_LOAD_DYLIB Addition","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Patching macOS Mach-O loader vulnerabilities eliminates the flaws that adversaries exploit to inject malicious dylibs through LC_LOAD_DYLIB header manipulation."},{"id":"T1546.010","name":"AppInit DLLs","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Patching AppInit DLL loading mechanisms in Windows eliminates the DLL injection vulnerability that adversaries exploit to load malicious code into every process importing user32.dll."},{"id":"T1546.011","name":"Application Shimming","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Patching the Application Compatibility Framework closes shim database vulnerabilities that adversaries exploit to inject code through application shimming for persistence."},{"id":"T1546.016","name":"Installer Packages","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Patching installer package handling vulnerabilities eliminates the privilege escalation flaws that adversaries exploit through malicious MSI or PKG installation packages."},{"id":"T1547.006","name":"Kernel Modules and Extensions","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Patching kernel module loading vulnerabilities and enforcing module signing eliminates the flaws that adversaries exploit to load malicious kernel modules for rootkit persistence."},{"id":"T1548.002","name":"Bypass User Account Control","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Patching UAC bypass vulnerabilities in Windows eliminates the specific elevation control flaws that adversaries use to silently escalate from standard user to administrator privileges."},{"id":"T1548.006","name":"TCC Manipulation","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Patching macOS TCC framework vulnerabilities closes the specific consent mechanism bypasses that adversaries exploit to grant malware access to protected resources without user approval."},{"id":"T1550.002","name":"Pass the Hash","tactics":["defense-evasion","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Patching NTLM authentication vulnerabilities and enabling Credential Guard reduces the effectiveness of pass-the-hash attacks by eliminating hash exposure and relay weaknesses."},{"id":"T1552.006","name":"Group Policy Preferences","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Remediating Group Policy Preferences credential storage ensures that cpassword values are removed from SYSVOL, eliminating the accessible credential source that adversaries target."},{"id":"T1553.006","name":"Code Signing Policy Modification","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Patching code signing policy enforcement vulnerabilities prevents adversaries from exploiting weaknesses in Windows or macOS signature verification to modify signing requirements."},{"id":"T1555.005","name":"Password Managers","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Patching password manager vulnerabilities closes the extraction and decryption flaws that adversaries exploit to retrieve stored credentials from browser-integrated and standalone password managers."},{"id":"T1559.002","name":"Dynamic Data Exchange","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Patching DDE handling in Office and other applications eliminates the dynamic data exchange execution vulnerabilities that adversaries exploit for document-based code execution."},{"id":"T1566.001","name":"Spearphishing Attachment","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Patching document rendering and attachment processing vulnerabilities reduces the exploitation surface that adversaries target with spearphishing attachments containing weaponized files."},{"id":"T1566.003","name":"Spearphishing via Service","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Patching service integration and message handling vulnerabilities closes the flaws that adversaries exploit in third-party messaging platforms for spearphishing delivery."},{"id":"T1574.002","name":"DLL Side-Loading","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Patching DLL side-loading vulnerabilities in applications ensures that programs properly validate loaded libraries, preventing adversaries from placing malicious DLLs alongside legitimate executables."},{"id":"T1574.013","name":"KernelCallbackTable","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Patching KernelCallbackTable handling vulnerabilities eliminates the callback table corruption flaws that adversaries exploit to redirect kernel-mode execution to malicious code."},{"id":"T1601.001","name":"Patch System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Applying firmware patches to network devices closes the specific vulnerabilities that adversaries exploit to modify the running system image and insert persistent backdoors."},{"id":"T1601.002","name":"Downgrade System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Keeping network device firmware current eliminates the known vulnerabilities present in older system images that adversaries exploit after forcing firmware downgrades."},{"id":"T1606.001","name":"Web Cookies","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Patching web cookie generation and validation libraries closes the specific cryptographic and session management flaws that adversaries exploit to forge session cookies."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: iso_27001_2022 A.6.8, A.8.32 added from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR entry 155), which OSA's mapping now takes as its base. 2026-10-03: nist_csf_2 ID.IM-01, ID.IM-02, ID.IM-03 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"corrective","used_by_patterns":["SP-001","SP-002","SP-011","SP-012","SP-023","SP-026","SP-028","SP-038","SP-043","SP-046","SP-050","SP-054"]}}