# SC-26 Decoys

NIST SP 800-53 control. Family: SC System and Communications Protection. Function: detective. In no baseline. Mapping licence: CC BY-SA 4.0.

Statement: Include components within organizational systems specifically designed to be the target of malicious attacks for detecting, deflecting, and analyzing such attacks.
Guidance: Decoys (i.e., honeypots, honeynets, or deception nets) are established to attract adversaries and deflect attacks away from the operational systems that support organizational mission and business functions. Use of decoys requires some supporting isolation measures to ensure that any deflected malicious code does not infect organizational systems. Depending on the specific usage of the decoy, consultation with the Office of the General Counsel before deployment may be needed.

## Enhancements (none current)
Withdrawn by NIST: SC-26(01) (now in SC-35).

## Clauses by framework (17 frameworks)
- pci_dss_v4: 11.1, 11.4
- mas_trm: 12
- rbi_csf: Annex1.13
- cbb_tm: TM-12
- cbuae: CR-3
- qatar_nia: CS
- sama_csf: 3.6
- bom_ctrm: 4.2
- cbe_csf: CD-1
- cbn_csf: Part3.5, Part4
- sa_js2: JS2-7.3
- bot_cyber: Ch3.1, Ch8.1
- cpmi_pfmi: CG.DE, CG.TE
- ecb_croe: CROE.2.4, CROE.2.6.2
- sebi_cscrf: DE.CM, SOC
- cbest: CBEST.4
- tiber_eu: TIBER.RT

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/SC-26
- Clauses only: /api/v1/controls/SC-26?fields=mappings
- Page for people: /controls/sc-26/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
