# SC-24 Fail in Known State

NIST SP 800-53 control. Family: SC System and Communications Protection. Function: preventative. Baselines: high. Mapping licence: CC BY-SA 4.0.

Statement: Fail to a [Assignment: organization-defined known system state] for the following failures on the indicated components while preserving [Assignment: organization-defined system state information] in failure: [Assignment: list of organization-defined types of system failures on organization-defined system components].
Guidance: Failure in a known state addresses security concerns in accordance with the mission and business needs of organizations. Failure in a known state prevents the loss of confidentiality, integrity, or availability of information in the event of failures of organizational systems or system components. Failure in a known safe state helps to prevent systems from failing to a state that may cause injury to individuals or destruction to property. Preserving system state information facilitates system restart and return to the operational mode with less disruption of mission and business processes.

## Clauses by framework (39 frameworks)
- cobit_2019: DSS05
- pci_dss_v4: 10.7
- nist_csf_2: PR.DS-10, PR.IR-03
- soc2_tsc: A1.2, CC7.4-POF5
- iso_42001_2023: A.4.5
- iec_62443: 3-3 SR 7.1, 3-3 SR 7.4
- nis2: Art. 21(2)(c)
- mas_trm: 8
- osfi_b13: B-13.2.6
- finma_circular: IV.B.d(59), IV.C(61), IV.C(70), IV.D(71), IV.E(87), IV.E(89), IV.E(90)
- gdpr: Art.32(1)(b)
- dora: Art.9(2), Art.11(4), Art.12(2)
- rbi_csf: Annex1.4
- fisc: FISC.O5
- lgpd_bcb: BCB.Art.7
- hkma_tme1: TME1.6.2
- cra: CRA.I.2k
- cbb_tm: TM-14
- cbuae: CR-13
- nca_ecc: 3-1, 3-2, 5-1
- bog_cisd: CISD-BCM
- bom_ctrm: 5.2
- cbe_csf: OVM-2
- cbn_csf: Part3.7
- sa_js2: JS2-7.5
- bcbs_239: Principle 5
- bot_cyber: Ch4.2
- cpmi_pfmi: CG.RR
- eba_ict: 3.7.3
- ecb_croe: CROE.2.5.2
- iosco_cyber: PFMI-17, RR-2, RR-3
- sebi_cscrf: RC.RP
- iaea_nss: Sec 8
- common_criteria: CC Part 2 — FPT
- fca_sysc_13: SYSC 13.8.2
- fda_cyber: SA-6
- lloyds_ms: MS8.6
- nhs_dspt: NDG-7.4
- solvency_ii: EIOPA-ICT-4.10
OSA's mapping for nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/SC-24
- Clauses only: /api/v1/controls/SC-24?fields=mappings
- Page for people: /controls/sc-24/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
