risk
Malware delivery, insertion and compromise of systems
Adversary crafts and delivers known, modified, or targeted malware (via email, web, removable media, or downloadable software) and compromises system software to take control, exfiltrate data, or degrade functions.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- cyber_security
- domain
- Secure Development (SDLC) & Application Security
- Network & Communications Security
- Vulnerability & Patch Management
- taxonomy
- nist-800-30-threat-event
- basel-operational-risk
- iso-27005-threat
- inherent_rating
- critical
Details
- risk_id
- sdlc-malware-injection-compromise
- category
- cyber_security
- likelihood
- high
- impact
- critical
- inherent_rating
- critical
- treatment
- mitigate
- taxonomies
- nist-800-30-threat-event
- basel-operational-risk
- iso-27005-threat
Source
No record-specific source URL is provided.
Connections
- UC-SDLC-11 — Apply specialized development to critical components mitigates Malware delivery, insertion and compromise of systems
- strength
- related
- rationale
- Custom-developing critical components avoids malicious code paths embedded in commercial/third-party software.
- UC-NET-10 — Deploy deception and dynamic detection capabilities mitigates Malware delivery, insertion and compromise of systems
- strength
- primary
- rationale
- Detonating suspicious files/URLs/code in isolated sandboxes before delivery and honeyclient identification of malicious code block malware delivery.
- UC-SDLC-05 — Enforce secure coding and input validation standards mitigates Malware delivery, insertion and compromise of systems
- strength
- related
- rationale
- Fewer exploitable coding defects reduce the footholds malware uses to compromise software.
- UC-BCDR-16 — Participate in cyber threat intelligence sharing mitigates Malware delivery, insertion and compromise of systems
- strength
- related
- rationale
- Shared malware indicators of compromise enable detection and blocking of known campaigns.
- UC-NET-13 — Control mobile code and web content mitigates Malware delivery, insertion and compromise of systems
- strength
- primary
- rationale
- Blocking unauthorized active/mobile code in browsers, documents, and email and filtering malicious websites prevents web/email malware delivery.
- UC-VULN-06 — Verify software, firmware, and information integrity mitigates Malware delivery, insertion and compromise of systems
- strength
- primary
- rationale
- File-integrity monitoring and signature/boot validation detect the unauthorized changes malware makes to system software, surfacing compromise.
- UC-ASSET-09 — Receive, analyze, and act on threat and vulnerability intelligence mitigates Malware delivery, insertion and compromise of systems
- strength
- related
- rationale
- Malware IOCs received via threat intelligence enable detection and blocking of active campaigns.
- UC-NET-12 — Restrict communication-capable devices, ports, and sensors mitigates Malware delivery, insertion and compromise of systems
- strength
- related
- rationale
- Disabling unneeded I/O device ports removes the removable-media vector for malware delivery.
- UC-VULN-05 — Block malware, spam, and phishing across all systems mitigates Malware delivery, insertion and compromise of systems
- strength
- primary
- rationale
- Centrally-managed anti-malware plus email/web filtering blocks and quarantines malware delivered via email, web, media, and downloads.
- UC-SDLC-04 — Engineer systems with secure architecture and design mitigates Malware delivery, insertion and compromise of systems
- strength
- related
- rationale
- Least privilege and process/memory isolation contain a compromise, limiting malware's blast radius.
- UC-SDLC-06 — Maintain configuration control over systems and code mitigates Malware delivery, insertion and compromise of systems
- strength
- related
- rationale
- Tracking integrity of changes to configuration items surfaces unauthorized/malicious modification of system software.
- UC-NET-06 — Enforce separation with hardware and software mechanisms mitigates Malware delivery, insertion and compromise of systems
- strength
- related
- rationale
- Non-modifiable executables and hardware write-protection resist malware tampering with critical code, but sandbox detonation (UC-NET-10) and mobile-code/web filtering (UC-NET-13) are the operative anti-malware-delivery defenses.