Non-persistence

LOW MODERATE HIGH
3 Enhancements 0 Overlays 3 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Implement non-persistent [system components and services] that are initiated in a known state and terminated [one of: upon end of session of use; ].

Discussion (NIST Supplemental Guidance)

Implementation of non-persistent components and services mitigates risk from advanced persistent threats (APTs) by reducing the targeting capability of adversaries (i.e., window of opportunity and available attack surface) to initiate and complete attacks. By implementing the concept of non-persistence for selected system components, organizations can provide a trusted, known state computing resource for a specific time period that does not give adversaries sufficient time to exploit vulnerabilities in organizational systems or operating environments. Since the APT is a high-end, sophisticated threat with regard to capability, intent, and targeting, organizations assume that over an extended period, a percentage of attacks will be successful. Non-persistent system components and services are activated as required using protected information and terminated periodically or at the end of sessions. Non-persistence increases the work factor of adversaries attempting to compromise or breach organizational systems. Non-persistence can be achieved by refreshing system components, periodically reimaging components, or using a variety of common virtualization techniques. Non-persistent services can be implemented by using virtualization techniques as part of virtual machines or as new instances of processes on physical machines (either persistent or non-persistent). The benefit of periodic refreshes of system components and services is that it does not require organizations to first determine whether compromises of components or services have occurred (something that may often be difficult to determine). The refresh of selected system components and services occurs with sufficient frequency to prevent the spread or intended impact of attacks, but not with such frequency that it makes the system unstable. Refreshes of critical components and services may be done periodically to hinder the ability of adversaries to exploit optimum windows of vulnerabilities.

Enhancements NIST SOURCE

SI-14(1) Refresh from Trusted Sources LOW MODERATE HIGH

Obtain software and data employed during system component and service refreshes from the following trusted sources: [trusted sources].

Discussion

Trusted sources include software and data from write-once, read-only media or from selected offline secure storage facilities.

Open full page for SI-14(1) →
SI-14(2) Non-persistent Information LOW MODERATE HIGH
  1. (a) [one of: refresh; generate on demand] ; and
  2. (b) Delete information when no longer needed.
Discussion

Retaining information longer than is needed makes the information a potential target for advanced adversaries searching for high value assets to compromise through unauthorized disclosure, unauthorized modification, or exfiltration. For system-related information, unnecessary retention provides advanced adversaries information that can assist in their reconnaissance and lateral movement through the system.

Open full page for SI-14(2) →
SI-14(3) Non-persistent Connectivity LOW MODERATE HIGH

Establish connections to the system on demand and terminate connections after [one of: completion of a request; a period of non-use].

Discussion

Persistent connections to systems can provide advanced adversaries with paths to move laterally through systems and potentially position themselves closer to high value assets. Limiting the availability of such connections impedes the adversary’s ability to move freely through organizational systems.

Open full page for SI-14(3) →

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for SI-14 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. non-persistent system components and services to be implemented are defined;
  2. one or more of the following PARAMETER VALUES is/are selected: {upon end of session of use; <SI-14_ODP[03] frequency>};
  3. the frequency at which to terminate non-persistent components and services that are initiated in a known state is defined (if selected);
  4. non-persistent <SI-14_ODP[01] system components and services> that are initiated in a known state are implemented;
  5. non-persistent <SI-14_ODP[01] system components and services> are terminated <SI-14_ODP[02] SELECTED PARAMETER VALUES>.

Examine

[SELECT FROM: System and information integrity policy; system and information integrity procedures; procedures addressing non-persistence for system components; system design documentation; system configuration settings and associated documentation; system audit records; system security plan; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel responsible for non-persistence; organizational personnel with information security responsibilities; system/network administrators; system developer].

Test

[SELECT FROM: Automated mechanisms supporting and/or implementing the initiation and termination of non-persistent components].

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for SI-14. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • System and information integrity policy
  • system security plan

Configuration

  • system design documentation
  • system configuration settings and associated documentation

Testing

  • Automated mechanisms supporting and/or implementing the initiation and termination of non-persistent components

Other Records

  • system and information integrity procedures
  • procedures addressing non-persistence for system components
  • system audit records
  • other relevant documents or records