Imported cross-references for EX-0010.05
These 152 mappings are SPARTA's own published cross-references: SPARTA lists the control against the technique and says nothing more about it. Every one of them is recorded as a relates_to mapping at moderate confidence, and that relationship and that confidence are SafeMode Space's, not SPARTA's. They record that the pairing came from SPARTA, not a judgement of how strongly it holds. Both are stated here rather than in a column because they are the same on every row. SafeMode Space did not adjudicate these individually and states no view on them; they are reproduced because they are useful and attributable. The reasoned mappings for this technique, with the written justification for each, are on the technique page.
Cross-references (152)
| Framework | Entry | Name | Referenced in |
|---|---|---|---|
| MITRE ATT&CK Enterprise | T1055 | Process Injection | SPARTA v4.0# |
| NIST SP 800-53 | AC-14 | Permitted Actions Without Identification or Authentication | SPARTA v4.0# |
| NIST SP 800-53 | AU-14 | Session Audit | SPARTA v4.0# |
| NIST SP 800-53 | AU-2 | Event Logging | SPARTA v4.0# |
| NIST SP 800-53 | AU-3 | Content of Audit Records | SPARTA v4.0# |
| NIST SP 800-53 | AU-3(1) | Additional Audit Information | SPARTA v4.0# |
| NIST SP 800-53 | AU-4 | Audit Log Storage Capacity | SPARTA v4.0# |
| NIST SP 800-53 | AU-4(1) | Transfer to Alternate Storage | SPARTA v4.0# |
| NIST SP 800-53 | AU-5 | Response to Audit Logging Process Failures | SPARTA v4.0# |
| NIST SP 800-53 | AU-5(2) | Real-time Alerts | SPARTA v4.0# |
| NIST SP 800-53 | AU-5(5) | Alternate Audit Logging Capability | SPARTA v4.0# |
| NIST SP 800-53 | AU-6(1) | Automated Process Integration | SPARTA v4.0# |
| NIST SP 800-53 | AU-6(4) | Central Review and Analysis | SPARTA v4.0# |
| NIST SP 800-53 | AU-8 | Time Stamps | SPARTA v4.0# |
| NIST SP 800-53 | AU-9 | Protection of Audit Information | SPARTA v4.0# |
| NIST SP 800-53 | AU-9(2) | Store on Separate Physical Systems or Components | SPARTA v4.0# |
| NIST SP 800-53 | AU-9(3) | Cryptographic Protection | SPARTA v4.0# |
| NIST SP 800-53 | CA-3 | Information Exchange | SPARTA v4.0# |
| NIST SP 800-53 | CA-7(6) | Automation Support for Monitoring | SPARTA v4.0# |
| NIST SP 800-53 | CA-8 | Penetration Testing | SPARTA v4.0# |
| NIST SP 800-53 | CA-8(1) | Independent Penetration Testing Agent or Team | SPARTA v4.0# |
| NIST SP 800-53 | CM-10 | Software Usage Restrictions | SPARTA v4.0# |
| NIST SP 800-53 | CM-10(1) | Open-source Software | SPARTA v4.0# |
| NIST SP 800-53 | CM-11 | User-installed Software | SPARTA v4.0# |
| NIST SP 800-53 | CM-11(3) | Automated Enforcement and Monitoring | SPARTA v4.0# |
| NIST SP 800-53 | CM-14 | Signed Components | SPARTA v4.0# |
| NIST SP 800-53 | CM-2 | Baseline Configuration | SPARTA v4.0# |
| NIST SP 800-53 | CM-4 | Impact Analyses | SPARTA v4.0# |
| NIST SP 800-53 | CM-4(2) | Verification of Controls | SPARTA v4.0# |
| NIST SP 800-53 | CM-5(6) | Limit Library Privileges | SPARTA v4.0# |
| NIST SP 800-53 | CM-7 | Least Functionality | SPARTA v4.0# |
| NIST SP 800-53 | CM-7(4) | Unauthorized Software — Deny-by-exception | SPARTA v4.0# |
| NIST SP 800-53 | CM-7(5) | Authorized Software — Allow-by-exception | SPARTA v4.0# |
| NIST SP 800-53 | CM-7(8) | Binary or Machine Executable Code | SPARTA v4.0# |
| NIST SP 800-53 | CM-8 | System Component Inventory | SPARTA v4.0# |
| NIST SP 800-53 | CM-8(7) | Centralized Repository | SPARTA v4.0# |
| NIST SP 800-53 | CP-10 | System Recovery and Reconstitution | SPARTA v4.0# |
| NIST SP 800-53 | CP-10(4) | Restore Within Time Period | SPARTA v4.0# |
| NIST SP 800-53 | CP-12 | Safe Mode | SPARTA v4.0# |
| NIST SP 800-53 | CP-2 | Contingency Plan | SPARTA v4.0# |
| NIST SP 800-53 | CP-2(5) | Continue Mission and Business Functions | SPARTA v4.0# |
| NIST SP 800-53 | CP-4(5) | Self-challenge | SPARTA v4.0# |
| NIST SP 800-53 | IA-2 | Identification and Authentication (Organizational Users) | SPARTA v4.0# |
| NIST SP 800-53 | IR-3 | Incident Response Testing | SPARTA v4.0# |
| NIST SP 800-53 | IR-3(1) | Automated Testing | SPARTA v4.0# |
| NIST SP 800-53 | IR-3(2) | Coordination with Related Plans | SPARTA v4.0# |
| NIST SP 800-53 | IR-4 | Incident Handling | SPARTA v4.0# |
| NIST SP 800-53 | IR-4(11) | Integrated Incident Response Team | SPARTA v4.0# |
| NIST SP 800-53 | IR-4(12) | Malicious Code and Forensic Analysis | SPARTA v4.0# |
| NIST SP 800-53 | IR-4(14) | Security Operations Center | SPARTA v4.0# |
| NIST SP 800-53 | IR-4(3) | Continuity of Operations | SPARTA v4.0# |
| NIST SP 800-53 | IR-4(5) | Automatic Disabling of System | SPARTA v4.0# |
| NIST SP 800-53 | IR-5 | Incident Monitoring | SPARTA v4.0# |
| NIST SP 800-53 | IR-5(1) | Automated Tracking, Data Collection, and Analysis | SPARTA v4.0# |
| NIST SP 800-53 | PE-10 | Emergency Shutoff | SPARTA v4.0# |
| NIST SP 800-53 | PE-11 | Emergency Power | SPARTA v4.0# |
| NIST SP 800-53 | PE-11(1) | Alternate Power Supply — Minimal Operational Capability | SPARTA v4.0# |
| NIST SP 800-53 | PE-14 | Environmental Controls | SPARTA v4.0# |
| NIST SP 800-53 | PL-8 | Security and Privacy Architectures | SPARTA v4.0# |
| NIST SP 800-53 | PL-8(1) | Defense in Depth | SPARTA v4.0# |
| NIST SP 800-53 | PM-5 | System Inventory | SPARTA v4.0# |
| NIST SP 800-53 | RA-10 | Threat Hunting | SPARTA v4.0# |
| NIST SP 800-53 | RA-3 | Risk Assessment | SPARTA v4.0# |
| NIST SP 800-53 | RA-3(4) | Predictive Cyber Analytics | SPARTA v4.0# |
| NIST SP 800-53 | RA-5 | Vulnerability Monitoring and Scanning | SPARTA v4.0# |
| NIST SP 800-53 | RA-5(11) | Public Disclosure Program | SPARTA v4.0# |
| NIST SP 800-53 | RA-5(3) | Breadth and Depth of Coverage | SPARTA v4.0# |
| NIST SP 800-53 | RA-7 | Risk Response | SPARTA v4.0# |
| NIST SP 800-53 | SA-10(1) | Software and Firmware Integrity Verification | SPARTA v4.0# |
| NIST SP 800-53 | SA-10(2) | Alternative Configuration Management Processes | SPARTA v4.0# |
| NIST SP 800-53 | SA-10(4) | Trusted Generation | SPARTA v4.0# |
| NIST SP 800-53 | SA-11 | Developer Testing and Evaluation | SPARTA v4.0# |
| NIST SP 800-53 | SA-11(1) | Static Code Analysis | SPARTA v4.0# |
| NIST SP 800-53 | SA-11(2) | Threat Modeling and Vulnerability Analyses | SPARTA v4.0# |
| NIST SP 800-53 | SA-11(3) | Independent Verification of Assessment Plans and Evidence | SPARTA v4.0# |
| NIST SP 800-53 | SA-11(4) | Manual Code Reviews | SPARTA v4.0# |
| NIST SP 800-53 | SA-11(5) | Penetration Testing | SPARTA v4.0# |
| NIST SP 800-53 | SA-11(6) | Attack Surface Reviews | SPARTA v4.0# |
| NIST SP 800-53 | SA-11(8) | Dynamic Code Analysis | SPARTA v4.0# |
| NIST SP 800-53 | SA-11(9) | Interactive Application Security Testing | SPARTA v4.0# |
| NIST SP 800-53 | SA-15 | Development Process, Standards, and Tools | SPARTA v4.0# |
| NIST SP 800-53 | SA-15(6) | Continuous Improvement | SPARTA v4.0# |
| NIST SP 800-53 | SA-15(7) | Automated Vulnerability Analysis | SPARTA v4.0# |
| NIST SP 800-53 | SA-15(8) | Reuse of Threat and Vulnerability Information | SPARTA v4.0# |
| NIST SP 800-53 | SA-2 | Allocation of Resources | SPARTA v4.0# |
| NIST SP 800-53 | SA-3 | System Development Life Cycle | SPARTA v4.0# |
| NIST SP 800-53 | SA-4(5) | System, Component, and Service Configurations | SPARTA v4.0# |
| NIST SP 800-53 | SA-4(9) | Functions, Ports, Protocols, and Services in Use | SPARTA v4.0# |
| NIST SP 800-53 | SA-8 | Security and Privacy Engineering Principles | SPARTA v4.0# |
| NIST SP 800-53 | SA-8(10) | Hierarchical Trust | SPARTA v4.0# |
| NIST SP 800-53 | SA-8(12) | Hierarchical Protection | SPARTA v4.0# |
| NIST SP 800-53 | SA-8(13) | Minimized Security Elements | SPARTA v4.0# |
| NIST SP 800-53 | SA-8(19) | Continuous Protection | SPARTA v4.0# |
| NIST SP 800-53 | SA-8(21) | Self-analysis | SPARTA v4.0# |
| NIST SP 800-53 | SA-8(22) | Accountability and Traceability | SPARTA v4.0# |
| NIST SP 800-53 | SA-8(23) | Secure Defaults | SPARTA v4.0# |
| NIST SP 800-53 | SA-8(24) | Secure Failure and Recovery | SPARTA v4.0# |
| NIST SP 800-53 | SA-8(25) | Economic Security | SPARTA v4.0# |
| NIST SP 800-53 | SA-8(26) | Performance Security | SPARTA v4.0# |
| NIST SP 800-53 | SA-8(29) | Repeatable and Documented Procedures | SPARTA v4.0# |
| NIST SP 800-53 | SA-8(3) | Modularity and Layering | SPARTA v4.0# |
| NIST SP 800-53 | SA-8(30) | Procedural Rigor | SPARTA v4.0# |
| NIST SP 800-53 | SA-8(31) | Secure System Modification | SPARTA v4.0# |
| NIST SP 800-53 | SA-8(4) | Partially Ordered Dependencies | SPARTA v4.0# |
| NIST SP 800-53 | SA-8(7) | Reduced Complexity | SPARTA v4.0# |
| NIST SP 800-53 | SA-9 | External System Services | SPARTA v4.0# |
| NIST SP 800-53 | SC-16(2) | Anti-spoofing Mechanisms | SPARTA v4.0# |
| NIST SP 800-53 | SC-2(2) | Disassociability | SPARTA v4.0# |
| NIST SP 800-53 | SC-24 | Fail in Known State | SPARTA v4.0# |
| NIST SP 800-53 | SC-32(1) | Separate Physical Domains for Privileged Functions | SPARTA v4.0# |
| NIST SP 800-53 | SC-5 | Denial-of-service Protection | SPARTA v4.0# |
| NIST SP 800-53 | SC-5(3) | Detection and Monitoring | SPARTA v4.0# |
| NIST SP 800-53 | SC-51 | Hardware-based Protection | SPARTA v4.0# |
| NIST SP 800-53 | SC-7(10) | Prevent Exfiltration | SPARTA v4.0# |
| NIST SP 800-53 | SC-7(29) | Separate Subnets to Isolate Functions | SPARTA v4.0# |
| NIST SP 800-53 | SC-7(9) | Restrict Threatening Outgoing Communications Traffic | SPARTA v4.0# |
| NIST SP 800-53 | SI-10(5) | Restrict Inputs to Trusted Sources and Approved Formats | SPARTA v4.0# |
| NIST SP 800-53 | SI-10(6) | Injection Prevention | SPARTA v4.0# |
| NIST SP 800-53 | SI-11 | Error Handling | SPARTA v4.0# |
| NIST SP 800-53 | SI-13 | Predictable Failure Prevention | SPARTA v4.0# |
| NIST SP 800-53 | SI-13(4) | Standby Component Installation and Notification | SPARTA v4.0# |
| NIST SP 800-53 | SI-16 | Memory Protection | SPARTA v4.0# |
| NIST SP 800-53 | SI-17 | Fail-safe Procedures | SPARTA v4.0# |
| NIST SP 800-53 | SI-3 | Malicious Code Protection | SPARTA v4.0# |
| NIST SP 800-53 | SI-3(10) | Malicious Code Analysis | SPARTA v4.0# |
| NIST SP 800-53 | SI-3(8) | Detect Unauthorized Commands | SPARTA v4.0# |
| NIST SP 800-53 | SI-4 | System Monitoring | SPARTA v4.0# |
| NIST SP 800-53 | SI-4(1) | System-wide Intrusion Detection System | SPARTA v4.0# |
| NIST SP 800-53 | SI-4(10) | Visibility of Encrypted Communications | SPARTA v4.0# |
| NIST SP 800-53 | SI-4(11) | Analyze Communications Traffic Anomalies | SPARTA v4.0# |
| NIST SP 800-53 | SI-4(13) | Analyze Traffic and Event Patterns | SPARTA v4.0# |
| NIST SP 800-53 | SI-4(16) | Correlate Monitoring Information | SPARTA v4.0# |
| NIST SP 800-53 | SI-4(17) | Integrated Situational Awareness | SPARTA v4.0# |
| NIST SP 800-53 | SI-4(2) | Automated Tools and Mechanisms for Real-time Analysis | SPARTA v4.0# |
| NIST SP 800-53 | SI-4(23) | Host-based Devices | SPARTA v4.0# |
| NIST SP 800-53 | SI-4(24) | Indicators of Compromise | SPARTA v4.0# |
| NIST SP 800-53 | SI-4(25) | Optimize Network Traffic Analysis | SPARTA v4.0# |
| NIST SP 800-53 | SI-4(4) | Inbound and Outbound Communications Traffic | SPARTA v4.0# |
| NIST SP 800-53 | SI-4(5) | System-generated Alerts | SPARTA v4.0# |
| NIST SP 800-53 | SI-4(7) | Automated Response to Suspicious Events | SPARTA v4.0# |
| NIST SP 800-53 | SI-6 | Security and Privacy Function Verification | SPARTA v4.0# |
| NIST SP 800-53 | SI-7 | Software, Firmware, and Information Integrity | SPARTA v4.0# |
| NIST SP 800-53 | SI-7(1) | Integrity Checks | SPARTA v4.0# |
| NIST SP 800-53 | SI-7(10) | Protection of Boot Firmware | SPARTA v4.0# |
| NIST SP 800-53 | SI-7(12) | Integrity Verification | SPARTA v4.0# |
| NIST SP 800-53 | SI-7(15) | Code Authentication | SPARTA v4.0# |
| NIST SP 800-53 | SI-7(17) | Runtime Application Self-protection | SPARTA v4.0# |
| NIST SP 800-53 | SI-7(5) | Automated Response to Integrity Violations | SPARTA v4.0# |
| NIST SP 800-53 | SI-7(6) | Cryptographic Protection | SPARTA v4.0# |
| NIST SP 800-53 | SI-7(8) | Auditing Capability for Significant Events | SPARTA v4.0# |
| NIST SP 800-53 | SI-7(9) | Verify Boot Process | SPARTA v4.0# |
| NIST SP 800-53 | SR-6(1) | Testing and Analysis | SPARTA v4.0# |