NIST 800-53 r5 · Controls catalogue · Family CM
CM-13Data Action Mapping
Develop and document a map of system data actions.
Last updated: 22 August 2026 07:11 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (0)
- No ATT&CK techniques mapped to this control yet.
Weaknesses this control addresses (8)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | 11,000+ | A data action map identifies locations where sensitive information may be exposed to unauthorized actors during processing or transfer. |
CWE-284 | Improper Access Control | 6,900+ | Mapping data actions reveals potential improper access controls by showing who can perform actions on data. |
CWE-285 | Improper Authorization | 1,500+ | Documenting data actions helps ensure proper authorization is enforced for each action involving sensitive data. |
CWE-532 | Insertion of Sensitive Information into Log File | 1,400+ | Identifying logging as a data action allows prevention of sensitive information being inserted into log files. |
CWE-319 | Cleartext Transmission of Sensitive Information | 1,000+ | Mapping transmission actions in data flows helps prevent cleartext transmission of sensitive information. |
CWE-312 | Cleartext Storage of Sensitive Information | 900+ | Data action mapping can detect storage actions that leave sensitive information in cleartext. |
CWE-311 | Missing Encryption of Sensitive Data | 500+ | The map highlights data actions that involve sensitive data, enabling identification of missing encryption requirements. |
CWE-538 | Insertion of Sensitive Information into Externally-Accessible File or Directory | 98 | The map shows if data actions result in sensitive information being placed in externally accessible locations. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
| No CVEs annotated to this control yet — the per-CVE backfill is in progress. | ||||