{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Vulnerability & Patch Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-VULN-09","description":"Reduce the attack surface available to persistent adversaries by provisioning selected components and services non-persistently and refreshing them from known-good, trusted sources at defined intervals or on demand. Refresh designated information at defined frequencies to purge stale or potentially corrupted data, source critical information from diverse suppliers or paths, and fragment designated high-value information across separate systems so no single compromise exposes or destroys it.","details":{"control_category":"technical","control_type":"preventive","domain":"Vulnerability & Patch Management","guidance":[],"members":[{"control_id":"SI-14","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SI-21","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SI-22","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SI-23","coverage":"full","framework":"nist-800-53","relationship":"superset_of"}],"statement":"Reduce the attack surface available to persistent adversaries by provisioning selected components and services non-persistently and refreshing them from known-good, trusted sources at defined intervals or on demand. Refresh designated information at defined frequencies to purge stale or potentially corrupted data, source critical information from diverse suppliers or paths, and fragment designated high-value information across separate systems so no single compromise exposes or destroys it.","title":"Employ non-persistence and information-resilience techniques","unified_id":"UC-VULN-09"},"id":"uc:UC-VULN-09","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-VULN-09","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"UC-VULN-09 — Employ non-persistence and information-resilience techniques","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:082beb85ae79b78d908264df9eca3922837ffbea679ceb0857fb9c86c4db3d4c","properties":{"rationale":"Sourcing critical data from diverse suppliers and refreshing/purging potentially corrupted data reduces reliance on any single poisoned source.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-09-01891801.json","sourceId":"uc:UC-VULN-09","targetDetailPath":"/data/v1/records/risk-ai-adversarial-poisoning-attacks-ea7df068.json","targetId":"risk:ai-adversarial-poisoning-attacks","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0962d8ae9406517ef0bf89d764bf181b00ab29b5a04bccb9ae99f0a8c463c5ee","properties":{"control_id":"SI-22","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-09-01891801.json","sourceId":"uc:UC-VULN-09","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-si-22-a90d31c3.json","targetId":"ctrl:nist-800-53:SI-22","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1e924ef949987025b493bbb7df32679b67a7f86b43be8655ed2d0ffdf20eee96","properties":{},"sourceDetailPath":"/data/v1/records/wf-c51-460f7a67.json","sourceId":"wf:C51","targetDetailPath":"/data/v1/records/uc-uc-vuln-09-01891801.json","targetId":"uc:UC-VULN-09","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6324e211c36ddc23bf111e1b3927baebd7d568821a831b9029979f2e2975bdf4","properties":{"control_id":"SI-14","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-09-01891801.json","sourceId":"uc:UC-VULN-09","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-si-14-64d121fa.json","targetId":"ctrl:nist-800-53:SI-14","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:67b598cbb0ad77f8264c073f930490bed11db861dbc01a3a9b3ffff53ad3522d","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-vuln-09-01891801.json","targetId":"uc:UC-VULN-09","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:74ac351c4577bdd841fbfeb6ab9ea5f1eb1e5284cfca4915f619d99947f7044c","properties":{"control_id":"SI-21","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-09-01891801.json","sourceId":"uc:UC-VULN-09","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-si-21-7d56f566.json","targetId":"ctrl:nist-800-53:SI-21","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bea763cca8575db826e4494f79b7e645a2532586ff244d14549f82205e1b235c","properties":{"control_id":"SI-23","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-09-01891801.json","sourceId":"uc:UC-VULN-09","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-si-23-94304a4e.json","targetId":"ctrl:nist-800-53:SI-23","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:eb92db02e2d2b5c8b8a77851e0e697fbeef61b8d8aa4d5a9b293e65885d627fc","properties":{"rationale":"Non-persistent provisioning and periodic refresh from known-good trusted sources revert configuration drift and unauthorized changes.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-09-01891801.json","sourceId":"uc:UC-VULN-09","targetDetailPath":"/data/v1/records/risk-config-poor-baseline-drift-2dd66324.json","targetId":"risk:config-poor-baseline-drift","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f3f40cfad72e696ffe8ca0681924d57b321303688a9c267f9f65d31c2560f714","properties":{"rationale":"Periodic non-persistent refresh evicts adversaries who exploited unknown vulnerabilities, limiting dwell when no patch exists.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-09-01891801.json","sourceId":"uc:UC-VULN-09","targetDetailPath":"/data/v1/records/risk-vuln-zero-day-a821d603.json","targetId":"risk:vuln-zero-day","type":"mitigates"}],"schemaVersion":1}
