Fail in Known State
LOW MODERATE ✓ HIGHRequirements NIST SOURCE
Fail to a [known system state] for the following failures on the indicated components while preserving [system state information] in failure: [types of system failures on system components].
Discussion (NIST Supplemental Guidance)
Failure in a known state addresses security concerns in accordance with the mission and business needs of organizations. Failure in a known state prevents the loss of confidentiality, integrity, or availability of information in the event of failures of organizational systems or system components. Failure in a known safe state helps to prevent systems from failing to a state that may cause injury to individuals or destruction to property. Preserving system state information facilitates system restart and return to the operational mode with less disruption of mission and business processes.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for SC-24 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- types of system failures for which the system components fail to a known state are defined;
- known system state to which system components fail in the event of a system failure is defined;
- system state information to be preserved in the event of a system failure is defined;
- <SC-24_ODP[01] types of system failures on system components> fail to a <SC-24_ODP[02] known system state> while preserving <SC-24_ODP[03] system state information> in failure.
Examine
[SELECT FROM: System and communications protection policy; procedures addressing system failure to known state; system design documentation; system configuration settings and associated documentation; list of failures requiring system to fail in a known state; state information to be preserved in system failure; system audit records; system security plan; other relevant documents or records].
Interview
[SELECT FROM: System/network administrators; organizational personnel with information security responsibilities; system developer].
Test
[SELECT FROM: Mechanisms supporting and/or implementing the fail in known state capability; mechanisms preserving system state information in the event of a system failure].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for SC-24. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- System and communications protection policy
- system security plan
Configuration
- system design documentation
- system configuration settings and associated documentation
Testing
- Mechanisms supporting and/or implementing the fail in known state capability
- mechanisms preserving system state information in the event of a system failure
Other Records
- procedures addressing system failure to known state
- list of failures requiring system to fail in a known state
- state information to be preserved in system failure
- system audit records
- other relevant documents or records