{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Vulnerability & Patch Management","type":"detective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-VULN-11","description":"Embed covert taint mechanisms — such as beacon files, honeytokens, or watermarked records — into organizational systems and datasets so that exfiltration, improper modification, or unauthorized use of data can be detected. Monitor for taint activations, alert the security team when they fire, and periodically test that the mechanisms remain functional.","details":{"control_category":"technical","control_type":"detective","domain":"Vulnerability & Patch Management","guidance":[],"members":[{"control_id":"SI-20","coverage":"full","framework":"nist-800-53","relationship":"equal"}],"statement":"Embed covert taint mechanisms — such as beacon files, honeytokens, or watermarked records — into organizational systems and datasets so that exfiltration, improper modification, or unauthorized use of data can be detected. Monitor for taint activations, alert the security team when they fire, and periodically test that the mechanisms remain functional.","title":"Embed taint mechanisms to detect data exfiltration","unified_id":"UC-VULN-11"},"id":"uc:UC-VULN-11","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-VULN-11","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"UC-VULN-11 — Embed taint mechanisms to detect data exfiltration","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8bb658f35c32a0817a7b43a736184336508319b56a26b4544d567448399f5c30","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-vuln-11-b9fdd819.json","targetId":"uc:UC-VULN-11","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b02b7dacbb987f3c2930ba7d2ab4f0f9a12bfd962a415497f62f4d6d2cbf7d3b","properties":{"control_id":"SI-20","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"equal","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-11-b9fdd819.json","sourceId":"uc:UC-VULN-11","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-si-20-e6c41fe9.json","targetId":"ctrl:nist-800-53:SI-20","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bd504bbf7741f5a45326b5447a0aa2154777b16ff90c30735225c85d804629eb","properties":{},"sourceDetailPath":"/data/v1/records/wf-c45-81c87a11.json","sourceId":"wf:C45","targetDetailPath":"/data/v1/records/uc-uc-vuln-11-b9fdd819.json","targetId":"uc:UC-VULN-11","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cf0005f9ca50ea2a3b5744e0e8b210a94efb318b29adc6553044f184c11e4e66","properties":{"rationale":"Taint activations detect exfiltration from exploitation of unknown vulnerabilities that preventive and signature controls missed.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-11-b9fdd819.json","sourceId":"uc:UC-VULN-11","targetDetailPath":"/data/v1/records/risk-vuln-zero-day-a821d603.json","targetId":"risk:vuln-zero-day","type":"mitigates"}],"schemaVersion":1}
