NIST 800-53 r5 · Controls catalogue · Family SC
SC-47Alternate Communications Paths
Establish {{ insert: param, sc-47_odp }} for system operations organizational command and control.
Last updated: 20 August 2026 13:14 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (0)
- No ATT&CK techniques mapped to this control yet.
Weaknesses this control addresses (8)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-400 | Uncontrolled Resource Consumption | 3,800+ | Alternate paths allow continued C2 operations when an attacker exploits resource-consumption weaknesses against the primary channel. |
CWE-770 | Allocation of Resources Without Limits or Throttling | 2,400+ | Unbounded allocation or throttling attacks on one path are contained; the alternate path preserves organizational command functions. |
CWE-693 | Protection Mechanism Failure | 700+ | Failure or compromise of the primary protection mechanism no longer results in total loss of C2 capability. |
CWE-653 | Improper Isolation or Compartmentalization | 73 | Providing a distinct alternate path directly implements compartmentalization of critical command-and-control communications. |
CWE-923 | Improper Restriction of Communication Channel to Intended Endpoints | 69 | Dedicated alternate paths enable explicit restriction of C2 traffic to intended endpoints rather than relying on a single unrestricted channel. |
CWE-405 | Asymmetric Resource Consumption (Amplification) | 51 | Amplification attacks that exhaust the primary path are mitigated by the existence of an independent alternate path for command traffic. |
CWE-657 | Violation of Secure Design Principles | 20 | Mandating redundant paths corrects the design-level omission of single points of failure for security-critical functions. |
CWE-406 | Insufficient Control of Network Message Volume (Network Amplification) | 19 | Network-volume amplification against one channel can be bypassed via the pre-established alternate path. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
| No CVEs annotated to this control yet — the per-CVE backfill is in progress. | ||||