Cyber Resilience

NIST 800-53 r5 · Controls catalogue · Family SC

SC-11Trusted Path

Provide a {{ insert: param, sc-11_odp.01 }} isolated trusted communications path for communications between the user and the trusted components of the system; and Permit users to invoke the trusted communications path for communications between the user and the following security functions of the system, including at a minimum, authentication and re-authentication: {{ insert: param, sc-11_odp.02 }}.

Last updated: 20 August 2026 13:14 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (0)

Weaknesses this control addresses (6)AI-assisted

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-346Origin Validation Error700+Trusted path establishment enforces validation that the communication originates from and reaches only the intended trusted system components.
CWE-290Authentication Bypass by Spoofing700+Isolated trusted path ensures the user interacts only with genuine system components, preventing spoofing of authentication interfaces or prompts.
CWE-288Authentication Bypass Using an Alternate Path or Channel600+Requires authentication to occur exclusively over the isolated trusted path, directly preventing bypass via alternate or untrusted channels.
CWE-923Improper Restriction of Communication Channel to Intended Endpoints69Mandates restriction of the channel for authentication to only the intended trusted endpoints, blocking unauthorized communication paths.
CWE-940Improper Verification of Source of a Communication Channel56Requires explicit verification of the source and integrity of the channel used for authentication and other security functions.
CWE-300Channel Accessible by Non-Endpoint55Explicitly isolates the communications path so it cannot be accessed or intercepted by non-endpoint entities during security functions.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2023-31004 6.18.30.0099good
CVE-2025-31214 6.18.10.0052good
CVE-2024-36553 6.08.10.0030good
CVE-2024-32049 5.77.40.0055good
CVE-2025-20122 5.67.80.0015good
CVE-2026-129915.58.70.0014good
CVE-2025-40770 5.37.40.0012good
CVE-2025-54792 5.16.80.0026good
CVE-2024-45407 5.06.50.0034good
CVE-2024-12602 4.76.20.0024good
CVE-2023-38272 4.65.90.0033good
CVE-2024-50568 4.65.90.0037good
CVE-2019-19751 4.45.60.0029good
CVE-2024-27263 4.15.30.0027good
CVE-2026-238103.54.30.0018good
CVE-2026-238113.54.30.0015good
CVE-2026-238123.54.30.0015good
CVE-2024-50565 2.83.10.0038good
CVE-2024-31206 6.28.20.0033good

Other controls in family SC

SC-1 SC-10 SC-12 SC-13 SC-14 SC-15 SC-16 SC-17 SC-18 SC-19 SC-2 SC-20 SC-21 SC-22 SC-23 SC-24 SC-25 SC-26 SC-27 SC-28 SC-29 SC-3 SC-30 SC-31 SC-32 SC-33 SC-34 SC-35 SC-36 SC-37 SC-38 SC-39 SC-4 SC-40 SC-41 SC-42 SC-43 SC-44 SC-45 SC-46 SC-47 SC-48 SC-49 SC-5 SC-50 SC-51 SC-6 SC-7 SC-8 SC-9