# SI-16 Memory Protection

NIST SP 800-53 control. Family: SI System and Information Integrity. Function: preventative. Baselines: moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: Implement the following controls to protect the system memory from unauthorized code execution: [Assignment: organization-defined controls].
Guidance: Some adversaries launch attacks with the intent of executing code in non-executable regions of memory or in memory locations that are prohibited. Controls employed to protect memory include data execution prevention and address space layout randomization. Data execution prevention controls can either be hardware-enforced or software-enforced with hardware enforcement providing the greater strength of mechanism.

## Clauses by framework (39 frameworks)
- cobit_2019: DSS05
- pci_dss_v4: 5.2, 6.2
- nist_csf_2: PR.DS-10
- cis_controls_v8: CIS 10, CIS 10.5, CIS 13.7
- iec_62443: 3-3 SR 3.4
- apra_cps_234: Para 22-23
- mas_trm: 11
- bsi_grundschutz: OPS.1.1.4, SYS.1.1, SYS.2.1
- anssi: Hygiene.21
- osfi_b13: B-13.3.2
- finma_circular: IV.C(64), IV.C(65)
- dora: Art.10(1)
- rbi_csf: Annex1.13
- fisc: FISC.T7
- hkma_tme1: TME1.7.3
- cra: CRA.I.2k
- cbuae: CR-7
- nca_ecc: 2-3, 2-14
- qatar_nia: OS
- sama_csf: 3.3
- uae_ia: T7
- bog_cisd: CISD-VI
- cbe_csf: CTO-7
- cbn_csf: Part3.3
- sa_js2: JS2-7.2, JS2-8.4
- bot_cyber: Ch2.6
- cpmi_pfmi: CG.PR
- ecb_croe: CROE.2.3.4
- ffiec_is: II.C.12
- iosco_cyber: DET-2
- sebi_cscrf: PR.ES
- cmmc_2: SI
- nrc_73_54: RG5.71-A-SI
- ieee_1686: 5.3
- pci_pts: B
- common_criteria: CC Part 2 — FPT
- fda_cyber: SA-3
- lloyds_ms: MS8.10
- owasp_masvs_v2: MASVS-CODE-4
OSA's mapping for nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/SI-16
- Clauses only: /api/v1/controls/SI-16?fields=mappings
- Page for people: /controls/si-16/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
