{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"cyber_security","domain":["Secure Development (SDLC) & Application Security","Network & Communications Security","Vulnerability & Patch Management"],"inherent_rating":"critical","taxonomy":["nist-800-30-threat-event","basel-operational-risk","iso-27005-threat"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Asdlc-malware-injection-compromise","description":"Adversary crafts and delivers known, modified, or targeted malware (via email, web, removable media, or downloadable software) and compromises system software to take control, exfiltrate data, or degrade functions.","details":{"category":"cyber_security","impact":"critical","inherent_rating":"critical","likelihood":"high","risk_id":"sdlc-malware-injection-compromise","taxonomies":["nist-800-30-threat-event","basel-operational-risk","iso-27005-threat"],"treatment":"mitigate"},"id":"risk:sdlc-malware-injection-compromise","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Asdlc-malware-injection-compromise","sourceIds":["aiuc-1","cobit-2019","dora","eu-ai-act","iso-27001","nist-800-53","nist-csf-2","pci-dss"],"sourceUrl":null,"title":"Malware delivery, insertion and compromise of systems","type":"risk"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1fd339e8dc8375611aaa45979ec3654de7f911719bbb713a6f461eb79b05fda3","properties":{"rationale":"Custom-developing critical components avoids malicious code paths embedded in commercial/third-party software.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-11-153d74aa.json","sourceId":"uc:UC-SDLC-11","targetDetailPath":"/data/v1/records/risk-sdlc-malware-injection-compromise-ec5a8dc4.json","targetId":"risk:sdlc-malware-injection-compromise","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4f767d2afd393943518c1c06ed602ce22fab6d9d5ef55c444a0c288244c659cc","properties":{"rationale":"Detonating suspicious files/URLs/code in isolated sandboxes before delivery and honeyclient identification of malicious code block malware delivery.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-net-10-81c56654.json","sourceId":"uc:UC-NET-10","targetDetailPath":"/data/v1/records/risk-sdlc-malware-injection-compromise-ec5a8dc4.json","targetId":"risk:sdlc-malware-injection-compromise","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:50d95fbb6889f0d7fdb1e036ecd4dcb095ce92de520eba8153febcc598d8b226","properties":{"rationale":"Fewer exploitable coding defects reduce the footholds malware uses to compromise software.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-05-053afd62.json","sourceId":"uc:UC-SDLC-05","targetDetailPath":"/data/v1/records/risk-sdlc-malware-injection-compromise-ec5a8dc4.json","targetId":"risk:sdlc-malware-injection-compromise","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6053c30f7892043bff62bcc4400882c794555c1031daf2351b4c1af6bc5883cf","properties":{"rationale":"Shared malware indicators of compromise enable detection and blocking of known campaigns.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-16-462251f1.json","sourceId":"uc:UC-BCDR-16","targetDetailPath":"/data/v1/records/risk-sdlc-malware-injection-compromise-ec5a8dc4.json","targetId":"risk:sdlc-malware-injection-compromise","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:62960c422c198d7937854108f2f52e093a484fc2e3a071629cdc824fd3e6449f","properties":{"rationale":"Blocking unauthorized active/mobile code in browsers, documents, and email and filtering malicious websites prevents web/email malware delivery.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-net-13-df790edf.json","sourceId":"uc:UC-NET-13","targetDetailPath":"/data/v1/records/risk-sdlc-malware-injection-compromise-ec5a8dc4.json","targetId":"risk:sdlc-malware-injection-compromise","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ab6ed02e59e1358d5166845047dda61fa3d1d05aa1125bbc710eb96ba9419b11","properties":{"rationale":"File-integrity monitoring and signature/boot validation detect the unauthorized changes malware makes to system software, surfacing compromise.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-06-3863b890.json","sourceId":"uc:UC-VULN-06","targetDetailPath":"/data/v1/records/risk-sdlc-malware-injection-compromise-ec5a8dc4.json","targetId":"risk:sdlc-malware-injection-compromise","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ab9edc61ab3338cd0b044ce5af4abc6b1acad35b761225fa037da13820b1a99b","properties":{"rationale":"Malware IOCs received via threat intelligence enable detection and blocking of active campaigns.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-09-911f6a6c.json","sourceId":"uc:UC-ASSET-09","targetDetailPath":"/data/v1/records/risk-sdlc-malware-injection-compromise-ec5a8dc4.json","targetId":"risk:sdlc-malware-injection-compromise","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ade03946e6f49daa08fd6d1182e2af00bdb409c3e5aa43a0398e6c499e81b96d","properties":{"rationale":"Disabling unneeded I/O device ports removes the removable-media vector for malware delivery.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-net-12-3fbb3db4.json","sourceId":"uc:UC-NET-12","targetDetailPath":"/data/v1/records/risk-sdlc-malware-injection-compromise-ec5a8dc4.json","targetId":"risk:sdlc-malware-injection-compromise","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dd7365a642246c5c4abf735b59d373cf7e7859e8f267ed2446f1704622c97b5b","properties":{"rationale":"Centrally-managed anti-malware plus email/web filtering blocks and quarantines malware delivered via email, web, media, and downloads.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-05-5870fcee.json","sourceId":"uc:UC-VULN-05","targetDetailPath":"/data/v1/records/risk-sdlc-malware-injection-compromise-ec5a8dc4.json","targetId":"risk:sdlc-malware-injection-compromise","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dfb54cca23622370cac3ee1362b8afcbe0e6e3a1a5231882cd4327d31b9e5638","properties":{"rationale":"Least privilege and process/memory isolation contain a compromise, limiting malware's blast radius.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-04-ee9d76b1.json","sourceId":"uc:UC-SDLC-04","targetDetailPath":"/data/v1/records/risk-sdlc-malware-injection-compromise-ec5a8dc4.json","targetId":"risk:sdlc-malware-injection-compromise","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fe5b9be8a462f95e221741fbbcd5f0671e7d5e41e5f3f91153380f74528c4a4f","properties":{"rationale":"Tracking integrity of changes to configuration items surfaces unauthorized/malicious modification of system software.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-06-c1afc713.json","sourceId":"uc:UC-SDLC-06","targetDetailPath":"/data/v1/records/risk-sdlc-malware-injection-compromise-ec5a8dc4.json","targetId":"risk:sdlc-malware-injection-compromise","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ffa21717c7b536b311576189f5ac36f3574b198353d58226190a8bc3f716acb6","properties":{"rationale":"Non-modifiable executables and hardware write-protection resist malware tampering with critical code, but sandbox detonation (UC-NET-10) and mobile-code/web filtering (UC-NET-13) are the operative anti-malware-delivery defenses.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-net-06-f006626f.json","sourceId":"uc:UC-NET-06","targetDetailPath":"/data/v1/records/risk-sdlc-malware-injection-compromise-ec5a8dc4.json","targetId":"risk:sdlc-malware-injection-compromise","type":"mitigates"}],"schemaVersion":1}
