{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Vulnerability & Patch Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-VULN-08","description":"Determine mean time to failure for components whose failure could compromise security or availability, and replace or refresh them within predicted tolerances before failure occurs. Define and implement fail-safe procedures so that on detected failure conditions systems enter a known safe state — preserving security protections, alerting designated personnel, and preventing unsafe continuation of operations.","details":{"control_category":"technical","control_type":"preventive","domain":"Vulnerability & Patch Management","guidance":[],"members":[{"control_id":"SI-13","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SI-17","coverage":"full","framework":"nist-800-53","relationship":"superset_of"}],"statement":"Determine mean time to failure for components whose failure could compromise security or availability, and replace or refresh them within predicted tolerances before failure occurs. Define and implement fail-safe procedures so that on detected failure conditions systems enter a known safe state — preserving security protections, alerting designated personnel, and preventing unsafe continuation of operations.","title":"Engineer systems to fail predictably and safely","unified_id":"UC-VULN-08"},"id":"uc:UC-VULN-08","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-VULN-08","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"UC-VULN-08 — Engineer systems to fail predictably and safely","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3e9b261c9d384f5191531b79aeabc2652f112f4a110e8d0f858d5681eab49816","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-vuln-08-0a9cdc47.json","targetId":"uc:UC-VULN-08","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4d02b25512a79224b1063a0a16bb06522c25dc9b0af115a676df173e94565e2e","properties":{"control_id":"SI-17","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-08-0a9cdc47.json","sourceId":"uc:UC-VULN-08","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-si-17-15626fd2.json","targetId":"ctrl:nist-800-53:SI-17","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:68349674078884030f9fc40ad511634f4e53eb9d8d66183b1619a7329e2a47be","properties":{"rationale":"On exploit-induced failure, failing to a known safe state preserves security protections and blocks unsafe continuation, limiting impact.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-08-0a9cdc47.json","sourceId":"uc:UC-VULN-08","targetDetailPath":"/data/v1/records/risk-vuln-zero-day-a821d603.json","targetId":"risk:vuln-zero-day","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b3441f87c6ceeb23ebfaa912c75b7402a2491597ff417c72dc25dcd21c11d4cd","properties":{},"sourceDetailPath":"/data/v1/records/wf-c40-440c22b9.json","sourceId":"wf:C40","targetDetailPath":"/data/v1/records/uc-uc-vuln-08-0a9cdc47.json","targetId":"uc:UC-VULN-08","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c0dfa63805a2d9ae2943a86ff1a0b8d7cbfea7d0435804ced0ed31309f2bbec0","properties":{"control_id":"SI-13","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-08-0a9cdc47.json","sourceId":"uc:UC-VULN-08","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-si-13-d41d19fb.json","targetId":"ctrl:nist-800-53:SI-13","type":"maps_to"}],"schemaVersion":1}
