NIST 800-53 r5 · Controls catalogue · Family SC
SC-16Transmission of Security and Privacy Attributes
Associate {{ insert: param, sc-16_prm_1 }} with information exchanged between systems and between system components.
Last updated: 22 August 2026 07:11 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (5)
Weaknesses this control addresses (5)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | 11,000+ | Associating security/privacy attributes with exchanged data enables receiving systems to enforce handling rules and avoid unauthorized disclosure. |
CWE-284 | Improper Access Control | 6,900+ | Transmitting bound security attributes preserves access-control context across system boundaries, directly reducing improper access control. |
CWE-285 | Improper Authorization | 1,500+ | Security attributes carried with data allow consistent authorization decisions between components and external systems. |
CWE-807 | Reliance on Untrusted Inputs in a Security Decision | 94 | Providing authoritative attributes with the data reduces the need for security decisions to rely on untrusted external inputs. |
CWE-501 | Trust Boundary Violation | 33 | Explicitly binding attributes to information crossing trust boundaries prevents loss of security context that leads to trust-boundary violations. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2024-44730 UPD | 6.8 | 9.1 | 0.0043 | partial |
CVE-2025-0592 UPD | 6.5 | 8.8 | 0.0035 | partial |
CVE-2019-25719 UPD | 6.3 | 8.6 | 0.0013 | partial |
CVE-2023-6408 UPD | 6.0 | 8.1 | 0.0032 | partial |
CVE-2024-43450 UPD | 5.8 | 7.5 | 0.0057 | partial |
CVE-2020-11639 UPD | 5.6 | 7.8 | 0.0013 | partial |
CVE-2024-8933 UPD | 5.6 | 7.5 | 0.0029 | partial |
CVE-2026-12576 | 5.6 | 7.5 | 0.0015 | partial |
CVE-2026-13584 | 5.5 | 7.1 | 0.0013 | partial |
CVE-2024-3371 UPD | 5.3 | 7.1 | 0.0023 | partial |
CVE-2024-12399 UPD | 5.2 | 7.1 | 0.0017 | partial |
CVE-2026-39827 UPD | 5.0 | 6.5 | 0.0028 | partial |
CVE-2024-39229 UPD | 4.1 | 5.3 | 0.0018 | partial |
CVE-2024-52288 UPD | 3.8 | 5.1 | 0.0013 | partial |
CVE-2026-14681 | 3.2 | 4.2 | 0.0008 | partial |
CVE-2026-54891 UPD | 3.0 | 3.7 | 0.0014 | partial |
CVE-2026-41120 | 7.3 | 9.8 | 0.0045 | partial |
CVE-2026-42960 UPD | 7.1 | 10.0 | 0.0025 | partial |
CVE-2026-45602 UPD | 6.8 | 9.1 | 0.0037 | partial |
CVE-2026-32162 | 6.7 | 8.4 | 0.0203 | partial |
CVE-2025-40778 UPD | 6.3 | 8.6 | 0.0066 | partial |
CVE-2026-50252 | 6.3 | 9.3 | 0.0014 | partial |
CVE-2024-9099 UPD | 6.2 | 8.1 | 0.0057 | partial |
CVE-2025-40776 UPD | 6.0 | 8.6 | 0.0020 | partial |
CVE-2025-0330 UPD | 5.9 | 7.5 | 0.0055 | partial |