# SC-35 External Malicious Code Identification

NIST SP 800-53 control. Family: SC System and Communications Protection. Function: preventative. In no baseline. Mapping licence: CC BY-SA 4.0.

Statement: Include system components that proactively seek to identify network-based malicious code or malicious websites.
Guidance: External malicious code identification differs from decoys in SC-26 in that the components actively probe networks, including the Internet, in search of malicious code contained on external websites. Like decoys, the use of external malicious code identification techniques requires some supporting isolation measures to ensure that any malicious code discovered during the search and subsequently executed does not infect organizational systems. Virtualization is a common technique for achieving such isolation.

## Clauses by framework (7 frameworks)
- pci_dss_v4: 5.3, 11.5
- nist_csf_2: DE.CM-09
- rbi_csf: Annex1.13
- cra: CRA.I.2k
- sebi_cscrf: DE.CM
- cbest: CBEST.4
- tiber_eu: TIBER.RT
OSA's mapping for nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/SC-35
- Clauses only: /api/v1/controls/SC-35?fields=mappings
- Page for people: /controls/sc-35/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
