{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Vulnerability & Patch Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-VULN-07","description":"Build and configure software so that failures and outputs cannot be weaponized: handle errors gracefully, generating only the minimum information needed for correction and revealing no sensitive data in messages or logs. Validate and filter information output from applications so it matches expected content and format before release to users or downstream systems. Enable hardware- and OS-level memory protections such as data-execution prevention and address-space layout randomization on all supporting systems.","details":{"control_category":"technical","control_type":"preventive","domain":"Vulnerability & Patch Management","guidance":[],"members":[{"control_id":"SI-11","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SI-15","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SI-16","coverage":"full","framework":"nist-800-53","relationship":"superset_of"}],"statement":"Build and configure software so that failures and outputs cannot be weaponized: handle errors gracefully, generating only the minimum information needed for correction and revealing no sensitive data in messages or logs. Validate and filter information output from applications so it matches expected content and format before release to users or downstream systems. Enable hardware- and OS-level memory protections such as data-execution prevention and address-space layout randomization on all supporting systems.","title":"Harden runtime error handling, output filtering, and memory","unified_id":"UC-VULN-07"},"id":"uc:UC-VULN-07","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-VULN-07","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"UC-VULN-07 — Harden runtime error handling, output filtering, and memory","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0d1462e1671fa28bd0d094d2d78205e874eec72cae32b613c734c2181fd4b36f","properties":{"rationale":"Graceful error handling, output filtering, and DEP/ASLR harden software so its inherent weaknesses cannot be weaponized.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-07-abfa5ce7.json","sourceId":"uc:UC-VULN-07","targetDetailPath":"/data/v1/records/risk-sdlc-vulnerabilities-in-software-10c28b16.json","targetId":"risk:sdlc-vulnerabilities-in-software","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:64ca0d68b5710570f75bcd1d65bd3e24832a12dd690a53084b69966190f1249a","properties":{"rationale":"Memory-protection mitigations reduce exploit success for known memory-corruption flaws pending a patch.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-07-abfa5ce7.json","sourceId":"uc:UC-VULN-07","targetDetailPath":"/data/v1/records/risk-vuln-unpatched-known-flaws-c4a6b075.json","targetId":"risk:vuln-unpatched-known-flaws","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6909cfdc8692f82582141d1712282b5b685e8c5c6c83e17dc119ee4dd824568c","properties":{},"sourceDetailPath":"/data/v1/records/wf-c46-88a88be6.json","sourceId":"wf:C46","targetDetailPath":"/data/v1/records/uc-uc-vuln-07-abfa5ce7.json","targetId":"uc:UC-VULN-07","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:92e3daed9da1a425643798aca3ce35d0cda3bb22e93b6e992c7eae67274cda75","properties":{},"sourceDetailPath":"/data/v1/records/wf-c10-29ff1ddb.json","sourceId":"wf:C10","targetDetailPath":"/data/v1/records/uc-uc-vuln-07-abfa5ce7.json","targetId":"uc:UC-VULN-07","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a3271f650ce9166df67a0d03571f82b4be6fce8c40b512352d08426acf3bf297","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-vuln-07-abfa5ce7.json","targetId":"uc:UC-VULN-07","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b3b8c7a0b4d981fb36558a9831dc84c53e2ba7d9262a65a71c93ad2bc924dcc5","properties":{"control_id":"SI-11","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-07-abfa5ce7.json","sourceId":"uc:UC-VULN-07","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-si-11-38e0a5a1.json","targetId":"ctrl:nist-800-53:SI-11","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bd03893a23dc08f61ce1dbb9f43871031e8a998416a7cdb69c59aecf01a77a8a","properties":{"control_id":"SI-15","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-07-abfa5ce7.json","sourceId":"uc:UC-VULN-07","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-si-15-e411f218.json","targetId":"ctrl:nist-800-53:SI-15","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d3d15083cf394800677b157e66aa6ee37fddf359a0b961664b54154b1203d3fc","properties":{"control_id":"SI-16","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-07-abfa5ce7.json","sourceId":"uc:UC-VULN-07","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-si-16-3a0ee4b1.json","targetId":"ctrl:nist-800-53:SI-16","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fccc8e725dda5b6c1b43e601d7c58d977a08ae2f91ddab77565bbaa1754ff03c","properties":{"rationale":"DEP/ASLR memory protections block reliable exploitation of unknown memory-corruption vulnerabilities before any patch exists.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-07-abfa5ce7.json","sourceId":"uc:UC-VULN-07","targetDetailPath":"/data/v1/records/risk-vuln-zero-day-a821d603.json","targetId":"risk:vuln-zero-day","type":"mitigates"}],"schemaVersion":1}
