{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Network & Communications Security","type":"detective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-NET-10","description":"Deploy decoy components (honeypots or honeynets) and honeyclient capabilities to attract, detect, and analyze malicious activity and externally hosted malicious code without exposing production assets. Detonate suspicious files, URLs, and code in isolated sandbox environments before delivery to users, and relocate or reposition detection sensors as threat conditions change.","details":{"control_category":"technical","control_type":"detective","domain":"Network & Communications Security","guidance":[],"members":[{"control_id":"SC-26","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SC-35","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SC-44","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SC-48","coverage":"full","framework":"nist-800-53","relationship":"superset_of"}],"statement":"Deploy decoy components (honeypots or honeynets) and honeyclient capabilities to attract, detect, and analyze malicious activity and externally hosted malicious code without exposing production assets. Detonate suspicious files, URLs, and code in isolated sandbox environments before delivery to users, and relocate or reposition detection sensors as threat conditions change.","title":"Deploy deception and dynamic detection capabilities","unified_id":"UC-NET-10"},"id":"uc:UC-NET-10","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-NET-10","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"UC-NET-10 — Deploy deception and dynamic detection capabilities","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:013ca4d097d52f82cf7b8ef2a6e92c8755852c0a49f29bcd1f50ce1083365687","properties":{"control_id":"SC-35","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-10-81c56654.json","sourceId":"uc:UC-NET-10","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-35-9dee5c25.json","targetId":"ctrl:nist-800-53:SC-35","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:19c81636e8fe4382bbdefb274c3591e8a861348d805aeceaaee72a2653359e94","properties":{"control_id":"SC-44","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-10-81c56654.json","sourceId":"uc:UC-NET-10","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-44-bde78c1c.json","targetId":"ctrl:nist-800-53:SC-44","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4f69872fc4f9967c616b4e358824ae4334b5e7ca3c837c4ae988e70113713d2c","properties":{"control_id":"SC-48","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-10-81c56654.json","sourceId":"uc:UC-NET-10","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-48-e6f8c9a4.json","targetId":"ctrl:nist-800-53:SC-48","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4f767d2afd393943518c1c06ed602ce22fab6d9d5ef55c444a0c288244c659cc","properties":{"rationale":"Detonating suspicious files/URLs/code in isolated sandboxes before delivery and honeyclient identification of malicious code block malware delivery.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-net-10-81c56654.json","sourceId":"uc:UC-NET-10","targetDetailPath":"/data/v1/records/risk-sdlc-malware-injection-compromise-ec5a8dc4.json","targetId":"risk:sdlc-malware-injection-compromise","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:97246b4508f8dd56391278489ec93fea81c8853b70e07d0584856073a3efccb9","properties":{},"sourceDetailPath":"/data/v1/records/wf-c45-81c87a11.json","sourceId":"wf:C45","targetDetailPath":"/data/v1/records/uc-uc-net-10-81c56654.json","targetId":"uc:UC-NET-10","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9e9d05d41254c047c0b61a5d96f7992dcc579591787f7bf4bdedd33c62cdd66e","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-net-10-81c56654.json","targetId":"uc:UC-NET-10","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ab58e8aa5154f1b752e0b131995aaf837f933662e33350df52ec6aca027d0f2b","properties":{"control_id":"SC-26","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-10-81c56654.json","sourceId":"uc:UC-NET-10","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-26-4fe06740.json","targetId":"ctrl:nist-800-53:SC-26","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:abf9226cdd511d30b5dcdf9023ebc5bac072b0807420c3975138b8c31f0ca33c","properties":{"rationale":"Decoy components attract and detect scanning and probing, revealing reconnaissance activity.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-net-10-81c56654.json","sourceId":"uc:UC-NET-10","targetDetailPath":"/data/v1/records/risk-cyber-reconnaissance-3a7a6c33.json","targetId":"risk:cyber-reconnaissance","type":"mitigates"}],"schemaVersion":1}
