Employ chosen technical and procedural means that corrupt the picture an adversary is working from. Misdirection routes hostile activity into deception environments, virtual sandboxes where malicious code can be diverted and adversary tradecraft safely observed. Tainting seeds data specifically so that its later appearance proves exfiltration occurred and may indicate where the adversary sits. Disinformation makes false claims about system state or defenses available to be found, whether tactically through decoy credentials that track adversary movement or strategically by devaluing what the adversary believes it has stolen. The effect sought is to frustrate reconnaissance, slow lateral movement, divert attention away from CUI and reveal the adversary's presence. Any disinformation activity is coordinated with the federal agency requiring it and planned so that authorized users are not caught by the false material.
NIST SP 800-172 3.13.3e is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-172 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 24 of 35 NIST SP 800-172 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 5 were rejected on the NIST SP 800-53 Rev 5 pair alone.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.