{"data":{"id":"SI-14","name":"Non-persistence","family":"SI","family_name":"System and Information Integrity","withdrawn":false,"description":"Implement non-persistent [Assignment: organization-defined system components and services] that are initiated in a known state and terminated [Selection (one or more): upon end of session of use; periodically at [Assignment: organization-defined frequency]].","supplemental_guidance":"Implementation of non-persistent components and services mitigates risk from advanced persistent threats (APTs) by reducing the targeting capability of adversaries (i.e., window of opportunity and available attack surface) to initiate and complete attacks. By implementing the concept of non-persistence for selected system components, organizations can provide a trusted, known state computing resource for a specific time period that does not give adversaries sufficient time to exploit vulnerabilities in organizational systems or operating environments. Since the APT is a high-end, sophisticated threat with regard to capability, intent, and targeting, organizations assume that over an extended period, a percentage of attacks will be successful. Non-persistent system components and services are activated as required using protected information and terminated periodically or at the end of sessions. Non-persistence increases the work factor of adversaries attempting to compromise or breach organizational systems.\n\nNon-persistence can be achieved by refreshing system components, periodically reimaging components, or using a variety of common virtualization techniques. Non-persistent services can be implemented by using virtualization techniques as part of virtual machines or as new instances of processes on physical machines (either persistent or non-persistent). The benefit of periodic refreshes of system components and services is that it does not require organizations to first determine whether compromises of components or services have occurred (something that may often be difficult to determine). The refresh of selected system components and services occurs with sufficient frequency to prevent the spread or intended impact of attacks, but not with such frequency that it makes the system unstable. Refreshes of critical components and services may be done periodically to hinder the ability of adversaries to exploit optimum windows of vulnerabilities.","enhancements":[{"id":"SI-14(01)","name":"Refresh from Trusted Sources","statement":"Obtain software and data employed during system component and service refreshes from the following trusted sources: [Assignment: organization-defined trusted sources].","baselines":[]},{"id":"SI-14(02)","name":"Non-persistent Information","statement":"a. [Selection (one): Refresh [Assignment: organization-defined information] [Assignment: organization-defined frequency]; Generate [Assignment: organization-defined information] on demand]; and\nb. Delete information when no longer needed.","baselines":[]},{"id":"SI-14(03)","name":"Non-persistent Connectivity","statement":"Establish connections to the system on demand and terminate connections after [Selection (one): completion of a request; a period of non-use].","baselines":[]}],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"nist_800_53":{"rev5":{"id":"SI-14","name":"Non-persistence","description":"Implement non-persistent [Assignment: organization-defined system components and services] that are initiated in a known state and terminated [Selection (one or more): upon end of session of use; periodically at [Assignment: organization-defined frequency]].","discussion":"Implementation of non-persistent components and services mitigates risk from advanced persistent threats (APTs) by reducing the targeting capability of adversaries (i.e., window of opportunity and available attack surface) to initiate and complete attacks. By implementing the concept of non-persistence for selected system components, organizations can provide a trusted, known state computing resource for a specific time period that does not give adversaries sufficient time to exploit vulnerabilities in organizational systems or operating environments. Since the APT is a high-end, sophisticated threat with regard to capability, intent, and targeting, organizations assume that over an extended period, a percentage of attacks will be successful. Non-persistent system components and services are activated as required using protected information and terminated periodically or at the end of sessions. Non-persistence increases the work factor of adversaries attempting to compromise or breach organizational systems.\n\nNon-persistence can be achieved by refreshing system components, periodically reimaging components, or using a variety of common virtualization techniques. Non-persistent services can be implemented by using virtualization techniques as part of virtual machines or as new instances of processes on physical machines (either persistent or non-persistent). The benefit of periodic refreshes of system components and services is that it does not require organizations to first determine whether compromises of components or services have occurred (something that may often be difficult to determine). The refresh of selected system components and services occurs with sufficient frequency to prevent the spread or intended impact of attacks, but not with such frequency that it makes the system unstable. Refreshes of critical components and services may be done periodically to hinder the ability of adversaries to exploit optimum windows of vulnerabilities.","related_controls":["SC-30","SC-34","SI-21"],"baseline_low":null,"baseline_moderate":null,"baseline_high":null,"baseline_privacy":null,"new_in_rev5":false,"changes_from_rev4":"No significant title changes from Rev 4."}},"compliance_mappings":{"iso_27001_2022":[],"iso_27002_2022":[],"cobit_2019":[],"pci_dss_v4":[],"nist_csf_2":[],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":[],"osfi_b13":[],"finma_circular":["IV.D(71)","IV.D(72)"],"gdpr":[],"dora":[],"bio2":[],"rbi_csf":["Annex1.5"],"fisc":[],"lgpd_bcb":[],"hkma_tme1":[],"mlps_2":[],"dnb_good_practice":[],"cra":[],"swift_cscf":[],"bot_cyber":["Ch10.1"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":[],"iso_27799":[],"lloyds_ms":[],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1505","name":"Server Software Component","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Non-persistent system components that are periodically refreshed or reimaged eliminate persistent server software components—web shells, malicious modules—by destroying modifications during each refresh cycle."},{"id":"T1505.001","name":"SQL Stored Procedures","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Periodic reimaging of database servers destroys malicious SQL stored procedures by restoring systems to known-good states, eliminating persistence that adversaries established through procedure modifications."},{"id":"T1505.002","name":"Transport Agent","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Non-persistent mail server components that are periodically refreshed eliminate malicious transport agents by reimaging Exchange servers to known-good configurations, removing persistent email interception mechanisms."},{"id":"T1505.004","name":"IIS Components","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Periodic refresh of web server instances destroys malicious IIS components by restoring known-good module configurations, eliminating persistent web traffic interception established through unauthorized module installation."},{"id":"T1546.003","name":"Windows Management Instrumentation Event Subscription","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Non-persistent system components that are periodically reimaged eliminate WMI event subscription persistence by destroying adversary-created event consumers during each system refresh cycle."},{"id":"T1547.004","name":"Winlogon Helper DLL","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Periodic reimaging of Windows systems destroys Winlogon Helper DLL persistence by restoring registry and file system to known-good states, eliminating unauthorized DLL loading during logon."},{"id":"T1547.006","name":"Kernel Modules and Extensions","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Non-persistent operating system instances that are periodically refreshed eliminate persistent kernel modules and extensions by reimaging to known-good kernel configurations, removing rootkit-level persistence."}],"metadata":{"last_reviewed":"2026-02-19","review_notes":"","mapping_status":"complete"},"function":"corrective","used_by_patterns":[]}}