{"data":{"id":"SI-16","name":"Memory Protection","family":"SI","family_name":"System and Information Integrity","withdrawn":false,"description":"Implement the following controls to protect the system memory from unauthorized code execution: [Assignment: organization-defined controls].","supplemental_guidance":"Some adversaries launch attacks with the intent of executing code in non-executable regions of memory or in memory locations that are prohibited. Controls employed to protect memory include data execution prevention and address space layout randomization. Data execution prevention controls can either be hardware-enforced or software-enforced with hardware enforcement providing the greater strength of mechanism.","enhancements":[],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"SI-16","name":"Memory Protection","description":"Implement the following controls to protect the system memory from unauthorized code execution: [Assignment: organization-defined controls].","discussion":"Some adversaries launch attacks with the intent of executing code in non-executable regions of memory or in memory locations that are prohibited. Controls employed to protect memory include data execution prevention and address space layout randomization. Data execution prevention controls can either be hardware-enforced or software-enforced with hardware enforcement providing the greater strength of mechanism.","related_controls":["AC-25","SC-03","SI-07"],"baseline_low":null,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":null,"new_in_rev5":false,"changes_from_rev4":"No significant title changes from Rev 4."}},"compliance_mappings":{"iso_27001_2022":[],"iso_27002_2022":[],"cobit_2019":["DSS05"],"pci_dss_v4":["5.2","6.2"],"nist_csf_2":["PR.DS-10"],"cis_controls_v8":["CIS 10","CIS 10.5","CIS 13.7"],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":["3-3 SR 3.4"],"asd_e8":[],"nis2":[],"apra_cps_234":["Para 22-23"],"mas_trm":["11"],"pra_op_resilience":[],"bsi_grundschutz":["OPS.1.1.4","SYS.1.1","SYS.2.1"],"anssi":["Hygiene.21"],"osfi_b13":["B-13.3.2"],"finma_circular":["IV.C(64)","IV.C(65)"],"gdpr":[],"dora":["Art.10(1)"],"bio2":[],"rbi_csf":["Annex1.13"],"fisc":["FISC.T7"],"lgpd_bcb":[],"hkma_tme1":["TME1.7.3"],"mlps_2":[],"dnb_good_practice":[],"cra":["CRA.I.2k"],"swift_cscf":[],"cbuae":["CR-7"],"nca_ecc":["2-3","2-14"],"qatar_nia":["OS"],"sama_csf":["3.3"],"uae_ia":["T7"],"bog_cisd":["CISD-VI"],"cbe_csf":["CTO-7"],"cbn_csf":["Part3.3"],"sa_js2":["JS2-7.2","JS2-8.4"],"bot_cyber":["Ch2.6"],"cpmi_pfmi":["CG.PR"],"ecb_croe":["CROE.2.3.4"],"ffiec_is":["II.C.12"],"iosco_cyber":["DET-2"],"sebi_cscrf":["PR.ES"],"cmmc_2":["SI"],"nerc_cip":[],"nrc_73_54":["RG5.71-A-SI"],"tsa_psd":[],"ieee_1686":["5.3"],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":["B"],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":["CC Part 2 — FPT"],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":["SA-3"],"hitrust_csf":[],"iso_27799":[],"lloyds_ms":["MS8.10"],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":["MASVS-CODE-4"],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1047","name":"Windows Management Instrumentation","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Memory protection controls including DEP and ASLR prevent WMI-based exploitation techniques that rely on predictable memory layouts or execution of injected shellcode in non-executable memory regions."},{"id":"T1059","name":"Command and Scripting Interpreter","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Memory protection through DEP prevents execution of adversary-injected code in data regions used by scripting interpreters, while ASLR makes exploitation of interpreter vulnerabilities unreliable."},{"id":"T1218","name":"System Binary Proxy Execution","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"DEP and ASLR protections on system binary processes prevent adversaries from exploiting memory corruption vulnerabilities in signed system utilities to achieve arbitrary code execution."},{"id":"T1543","name":"Create or Modify System Process","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Memory protection on service host processes prevents exploitation of buffer overflows in system services that adversaries target for persistent, privileged code execution through process creation."},{"id":"T1548","name":"Abuse Elevation Control Mechanism","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"DEP and ASLR on privilege elevation mechanisms prevent memory corruption exploits targeting UAC, sudo, or setuid binaries that adversaries use to bypass elevation controls."},{"id":"T1565","name":"Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Memory integrity protections including DEP and guard pages detect and prevent unauthorized modification of runtime data structures through buffer overflows or out-of-bounds writes."},{"id":"T1611","name":"Escape to Host","tactics":["privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Memory protection boundaries between container processes and host kernel, including seccomp and DEP enforcement, prevent exploitation of memory corruption vulnerabilities for container escape."},{"id":"T1003.001","name":"LSASS Memory","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Protected Process Light and Credential Guard memory protection prevent unauthorized processes from reading LSASS memory regions where cached credentials and Kerberos tickets are stored."},{"id":"T1055.009","name":"Proc Memory","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"DEP enforcement prevents injected code from executing in process memory regions marked as non-executable, while ASLR randomizes memory layouts to make /proc/pid/mem injection unreliable."},{"id":"T1059.001","name":"PowerShell","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"AMSI integration with memory protection prevents PowerShell from executing malicious scripts that have been dynamically loaded into memory, including fileless attack payloads."},{"id":"T1059.002","name":"AppleScript","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Memory protection on the AppleScript runtime prevents exploitation of interpreter vulnerabilities and blocks execution of injected code in non-executable memory regions."},{"id":"T1059.003","name":"Windows Command Shell","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"DEP enforcement prevents adversary shellcode from executing within cmd.exe process memory by blocking code execution in non-executable data regions, countering memory-based attacks that bypass disk-based detection."},{"id":"T1059.004","name":"Unix Shell","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Memory protection on Unix shell processes through W^X enforcement prevents execution of adversary-injected code in writable memory regions used by shell interpreters."},{"id":"T1059.005","name":"Visual Basic","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"DEP and ASLR on Visual Basic runtime environments prevent exploitation of VB interpreter vulnerabilities and block execution of injected code in non-executable memory."},{"id":"T1059.006","name":"Python","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Memory protection on Python interpreter processes prevents adversaries from exploiting buffer overflows or executing shellcode injected into Python's memory space."},{"id":"T1059.007","name":"JavaScript","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"DEP and ASLR on JavaScript engines prevent memory corruption exploits targeting V8, SpiderMonkey, or other JS runtime environments for arbitrary code execution."},{"id":"T1059.008","name":"Network Device CLI","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Memory protection on network device operating systems prevents exploitation of CLI interface buffer overflows that adversaries target for command execution on network infrastructure."},{"id":"T1059.011","name":"Lua","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Memory protection on Lua interpreter processes prevents exploitation of interpreter vulnerabilities and blocks adversary execution of shellcode in Lua runtime memory regions."},{"id":"T1218.001","name":"Compiled HTML File","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"DEP enforcement prevents execution of malicious shellcode embedded in compiled HTML files that attempt to exploit the HTML Help viewer's memory space."},{"id":"T1218.002","name":"Control Panel","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Memory protection on the Control Panel host process prevents exploitation of memory corruption vulnerabilities in .cpl file loading that adversaries target for code execution."},{"id":"T1218.003","name":"CMSTP","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"DEP and ASLR on the CMSTP.exe process prevent memory corruption exploits targeting the Connection Manager installation utility for arbitrary code execution."},{"id":"T1218.004","name":"InstallUtil","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Memory protection on the InstallUtil.exe process prevents exploitation of .NET assembly loading mechanisms through buffer overflows or memory corruption in the installer utility."},{"id":"T1218.005","name":"Mshta","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"DEP enforcement on Mshta.exe prevents adversary shellcode from executing within the HTML Application host's memory space when processing malicious HTA content."},{"id":"T1218.008","name":"Odbcconf","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Memory protection on Odbcconf.exe prevents memory corruption exploits targeting the ODBC configuration utility that adversaries abuse for DLL loading and execution."},{"id":"T1218.009","name":"Regsvcs/Regasm","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"DEP and ASLR on Regsvcs/Regasm processes prevent exploitation of .NET COM registration utilities through memory corruption attacks targeting managed assembly loading."},{"id":"T1218.012","name":"Verclsid","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Memory protection on Verclsid.exe prevents adversary exploitation of COM verification processes through buffer overflows or memory injection in the class ID verification utility."},{"id":"T1218.013","name":"Mavinject","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"DEP enforcement prevents adversary shellcode from executing within Mavinject.exe memory space during DLL injection operations, blocking memory corruption exploits that target the process injection utility."},{"id":"T1218.014","name":"MMC","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Memory protection on the MMC process prevents exploitation of snap-in loading mechanisms through memory corruption attacks targeting the Microsoft Management Console."},{"id":"T1218.015","name":"Electron Applications","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"DEP and ASLR on Electron application processes prevent exploitation of Chromium-based rendering engine memory corruption vulnerabilities for arbitrary code execution."},{"id":"T1505.004","name":"IIS Components","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Memory protection on IIS worker processes prevents exploitation of buffer overflows in IIS components that adversaries target for installing persistent server-side backdoors."},{"id":"T1543.002","name":"Systemd Service","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Memory protection on systemd and service processes prevents exploitation of buffer overflows that adversaries target for creating persistent privileged services on Linux systems."},{"id":"T1547.004","name":"Winlogon Helper DLL","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"DEP enforcement on the Winlogon process prevents adversary shellcode execution through Winlogon Helper DLL loading, as injected code in non-executable regions is blocked."},{"id":"T1547.006","name":"Kernel Modules and Extensions","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Kernel memory protection including SMEP and SMAP prevents exploitation of kernel module loading mechanisms through memory corruption, blocking unauthorized kernel-level persistence."},{"id":"T1548.004","name":"Elevated Execution with Prompt","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Memory protection on macOS authorization prompts prevents exploitation of elevation dialog memory corruption that adversaries could use to bypass prompted privilege escalation."},{"id":"T1565.001","name":"Stored Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Memory integrity protections including guard pages and canaries detect buffer overflows targeting stored data structures, preventing undetected manipulation of persistent application data."},{"id":"T1565.003","name":"Runtime Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"DEP, ASLR, and Control Flow Integrity mechanisms prevent adversary exploitation of memory corruption to manipulate runtime data in application processes for operational impact."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: nist_csf_2 PR.DS-10 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"preventative","used_by_patterns":[]}}