NIST 800-53 r5 · Controls catalogue · Family SC
SC-36Distributed Processing and Storage
Distribute the following processing and storage components across multiple {{ insert: param, sc-36_prm_1 }}: {{ insert: param, sc-36_prm_2 }}.
Last updated: 22 August 2026 07:11 UTC
Implementations targeting this control (4)
- aws-config-dynamodb-autoscaling-enabled Dynamodb Autoscaling Enabled AWS::DynamoDB::Table partial protect enforce
- aws-config-elb-cross-zone-load-balancing-enabled Elb Cross Zone Load Balancing Enabled AWS::ElasticLoadBalancing::LoadBalancer partial protect enforce
- aws-config-rds-multi-az-support Rds Multi Az Support AWS::RDS::DBInstance partial protect enforce CIS v5 §2.2.4Hub RDS.5
- aws-config-vpc-vpn-2-tunnels-up Vpc Vpn 2 Tunnels Up AWS::EC2::VPC partial protect enforce
ATT&CK techniques this control mitigates (7)
Weaknesses this control addresses (5)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-284 | Improper Access Control | 6,900+ | Distribution forces an attacker to compromise multiple independent components rather than a single centralized target, directly reducing the impact of access control failures. |
CWE-400 | Uncontrolled Resource Consumption | 3,800+ | Spreading processing and storage across locations prevents a single resource pool from being exhausted by one attack, mitigating uncontrolled consumption. |
CWE-770 | Allocation of Resources Without Limits or Throttling | 2,400+ | Decentralized allocation inherently caps the resources available to any one component or attacker, countering unbounded allocation weaknesses. |
CWE-668 | Exposure of Resource to Wrong Sphere | 800+ | Placing components in separate spheres limits the blast radius of any exposure, reducing the chance that a resource is reachable from an unintended domain. |
CWE-653 | Improper Isolation or Compartmentalization | 73 | Explicitly distributes components to achieve compartmentalization, making it harder to exploit weak isolation boundaries between processing or storage elements. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
| No CVEs annotated to this control yet — the per-CVE backfill is in progress. | ||||