NIST SP 800-172
SC

NIST SP 800-172 3.13.2e: Introduce Unpredictability into System Operations

Make a defined set of changes to systems and system components, at a defined frequency, so that the attack surface stops presenting a fixed and predictable target. Attack planning assumes consistency in the points where an adversary can enter, act or extract data, so varying the timing and circumstances of routine actions removes that assumption. Shortening credential validity at irregular intervals, performing routine activities at different times of day, alternating between technologies or suppliers, and rotating the roles and responsibilities of personnel all inject uncertainty. The intent is to force miscalculation, delay adversary action, and make attackers more observable when they do move. The organization decides which changes qualify and how often each system and component receives them.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 60 controls across 19 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27001:2022 · 6 controls

  • 5.8 Information security in project management
  • 8.18 Use of privileged utility programs
  • 8.25 Secure development life cycle
  • 8.26 Application security requirements
  • 8.27 Secure system architecture and engineering principles
  • 8.3 Information access restriction

ISO 27002:2022 · 6 controls

  • 5.8 Information security in project management
  • 8.18 Use of privileged utility programs
  • 8.25 Secure development life cycle
  • 8.26 Application security requirements
  • 8.27 Secure system architecture and engineering principles
  • 8.3 Information access restriction
  • ASBv3-AM-4 Limit access to asset management
  • ASBv3-DS-3 Secure DevOps infrastructure
  • ASBv3-PA-7 Follow just enough administration (least privilege) principle
  • PA-1 Separate and limit highly privileged/administrative users

CIS Controls v8 · 4 controls

  • CIS-16.1 Establish and Maintain a Secure Application Development Process
  • CIS-16.10 Apply Secure Design Principles in Application Architectures
  • CIS-5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts
  • CIS-6.8 Define and Maintain Role-Based Access Control

CMMC 2.0 · 4 controls

NIST SP 800-53 Rev 5 · 4 controls

PCI DSS 4.0 · 4 controls

  • 6.2.1 6.2.1 Secure development of bespoke and custom software
  • 7.2.1 7.2.1 Access control model defined
  • 7.2.2 7.2.2 User access assigned by job function and least privilege
  • 7.3.3 7.3.3 Access control default deny all

FedRAMP High · 3 controls

  • AC-6 Least Privilege
  • AC-6(1) Authorize Access to Security Functions
  • SA-8 Security and Privacy Engineering Principles

FedRAMP Moderate · 3 controls

  • AC-6 Least Privilege
  • AC-6(1) Authorize Access to Security Functions
  • SA-8 Security and Privacy Engineering Principles

NIST SP 800-161 Rev 1 · 3 controls

NIST SP 800-171 Rev 3 · 3 controls

NIST SP 800-218 · 3 controls

  • ANSSI-HYG-09 Assign the Correct Rights on Sensitive Resources
  • ANSSI-HYG-29 Limit Administration Rights on Workstations to Operational Need
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle

SOC 2 · 2 controls

  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties

C5 (Germany) · 1 control

HIPAA Security Rule · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in SC

You are reading one control. How much of NIST SP 800-172 have you already done?

NIST SP 800-172 3.13.2e is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-172 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 24 of 35 NIST SP 800-172 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 5 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 60 it maps to, and the evidence behind each claim, over MCP and REST.