Concealment and Misdirection

LOW MODERATE HIGH
4 Enhancements 0 Overlays 6 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Employ the following concealment and misdirection techniques for [systems] at [time periods] to confuse and mislead adversaries: [concealment and misdirection techniques].

Discussion (NIST Supplemental Guidance)

Concealment and misdirection techniques can significantly reduce the targeting capabilities of adversaries (i.e., window of opportunity and available attack surface) to initiate and complete attacks. For example, virtualization techniques provide organizations with the ability to disguise systems, potentially reducing the likelihood of successful attacks without the cost of having multiple platforms. The increased use of concealment and misdirection techniques and methods—including randomness, uncertainty, and virtualization—may sufficiently confuse and mislead adversaries and subsequently increase the risk of discovery and/or exposing tradecraft. Concealment and misdirection techniques may provide additional time to perform core mission and business functions. The implementation of concealment and misdirection techniques may add to the complexity and management overhead required for the system.

Enhancements NIST SOURCE

SC-30(1) Virtualization Techniques WITHDRAWN

Withdrawn. Incorporated into SC-29(1).

SC-30(2) Randomness LOW MODERATE HIGH

Employ [techniques] to introduce randomness into organizational operations and assets.

Discussion

Randomness introduces increased levels of uncertainty for adversaries regarding the actions that organizations take to defend their systems against attacks. Such actions may impede the ability of adversaries to correctly target information resources of organizations that support critical missions or business functions. Uncertainty may also cause adversaries to hesitate before initiating or continuing attacks. Misdirection techniques that involve randomness include performing certain routine actions at different times of day, employing different information technologies, using different suppliers, and rotating roles and responsibilities of organizational personnel.

Open full page for SC-30(2) →
SC-30(3) Change Processing and Storage Locations LOW MODERATE HIGH

Change the location of [processing and/or storage][one of: ; random time intervals]].

Discussion

Adversaries target critical mission and business functions and the systems that support those mission and business functions while also trying to minimize the exposure of their existence and tradecraft. The static, homogeneous, and deterministic nature of organizational systems targeted by adversaries make such systems more susceptible to attacks with less adversary cost and effort to be successful. Changing processing and storage locations (also referred to as moving target defense) addresses the advanced persistent threat using techniques such as virtualization, distributed processing, and replication. This enables organizations to relocate the system components (i.e., processing, storage) that support critical mission and business functions. Changing the locations of processing activities and/or storage sites introduces a degree of uncertainty into the targeting activities of adversaries. The targeting uncertainty increases the work factor of adversaries and makes compromises or breaches of the organizational systems more difficult and time-consuming. It also increases the chances that adversaries may inadvertently disclose certain aspects of their tradecraft while attempting to locate critical organizational resources.

Open full page for SC-30(3) →
SC-30(4) Misleading Information LOW MODERATE HIGH

Employ realistic, but misleading information in [system components] about its security state or posture.

Discussion

Employing misleading information is intended to confuse potential adversaries regarding the nature and extent of controls deployed by organizations. Thus, adversaries may employ incorrect and ineffective attack techniques. One technique for misleading adversaries is for organizations to place misleading information regarding the specific controls deployed in external systems that are known to be targeted by adversaries. Another technique is the use of deception nets that mimic actual aspects of organizational systems but use, for example, out-of-date software configurations.

Open full page for SC-30(4) →
SC-30(5) Concealment of System Components LOW MODERATE HIGH

Employ the following techniques to hide or conceal [system components]: [techniques].

Discussion

By hiding, disguising, or concealing critical system components, organizations may be able to decrease the probability that adversaries target and successfully compromise those assets. Potential means to hide, disguise, or conceal system components include the configuration of routers or the use of encryption or virtualization techniques.

Open full page for SC-30(5) →

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for SC-30 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. concealment and misdirection techniques to be employed to confuse and mislead adversaries potentially targeting systems are defined;
  2. systems for which concealment and misdirection techniques are to be employed are defined;
  3. time periods to employ concealment and misdirection techniques for systems are defined;
  4. <SC-30_ODP[01] concealment and misdirection techniques> are employed for <SC-30_ODP[02] systems> for <SC-30_ODP[03] time periods> to confuse and mislead adversaries.

Examine

[SELECT FROM: System and communications protection policy; procedures addressing concealment and misdirection techniques for the system; system design documentation; system configuration settings and associated documentation; system architecture; list of concealment and misdirection techniques to be employed for organizational systems; system audit records; system security plan; other relevant documents or records].

Interview

[SELECT FROM: System/network administrators; organizational personnel with information security responsibilities; organizational personnel with the responsibility to implement concealment and misdirection techniques for systems].

Test

[SELECT FROM: Mechanisms supporting and/or implementing concealment and misdirection techniques].

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for SC-30. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • System and communications protection policy
  • system security plan

Configuration

  • system design documentation
  • system configuration settings and associated documentation
  • system architecture

Testing

  • Mechanisms supporting and/or implementing concealment and misdirection techniques

Other Records

  • procedures addressing concealment and misdirection techniques for the system
  • list of concealment and misdirection techniques to be employed for organizational systems
  • system audit records
  • other relevant documents or records