# SC-44 Detonation Chambers

NIST SP 800-53 control. Family: SC System and Communications Protection. Function: preventative. In no baseline. Mapping licence: CC BY-SA 4.0.

Statement: Employ a detonation chamber capability within [Assignment: organization-defined system, system component, or location].
Guidance: Detonation chambers, also known as dynamic execution environments, allow organizations to open email attachments, execute untrusted or suspicious applications, and execute Universal Resource Locator requests in the safety of an isolated environment or a virtualized sandbox. Protected and isolated execution environments provide a means of determining whether the associated attachments or applications contain malicious code. While related to the concept of deception nets, the employment of detonation chambers is not intended to maintain a long-term environment in which adversaries can operate and their actions can be observed. Rather, detonation chambers are intended to quickly identify malicious code and either reduce the likelihood that the code is propagated to user environments of operation or prevent such propagation completely.

## Clauses by framework (32 frameworks)
- iso_27002_2022: 8.7
- cobit_2019: DSS05
- pci_dss_v4: 5.2
- cis_controls_v8: CIS 10, CIS 10.7
- mas_trm: 12
- bsi_grundschutz: APP.1.1, OPS.1.1.4
- anssi: Hygiene.21
- osfi_b13: B-13.3.2
- finma_circular: IV.C(64), IV.C(65)
- bio2: 8.7
- rbi_csf: Annex1.13
- dnb_good_practice: DNB.19.1
- cra: CRA.I.2i
- cbb_tm: TM-8, TM-12
- cbuae: CR-3
- qatar_nia: CS
- sama_csf: 3.6
- bom_ctrm: 4.2
- cbe_csf: CD-1, CTO-6
- cbn_csf: Part3.5, Part4
- sa_js2: JS2-7.3, JS2-8.4
- bot_cyber: Ch3.1
- ecb_croe: CROE.2.3.5
- ffiec_is: II.C.9, II.C.12
- hipaa_sr: §164.308(a)(5)(ii)(B)
- nydfs_500: 500.14
- sebi_cscrf: DE.DP, PR.NS
- hitrust_csf: 09.c
- iso_27799: 12.2
- lloyds_ms: MS8.10
- naic_ds: 4-monitoring
- nhs_dspt: NDG-9.3

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/SC-44
- Clauses only: /api/v1/controls/SC-44?fields=mappings
- Page for people: /controls/sc-44/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
