NIST 800-53 r5 · Controls catalogue · Family SC
SC-5Denial-of-service Protection
{{ insert: param, sc-05_odp.02 }} the effects of the following types of denial-of-service events: {{ insert: param, sc-05_odp.01 }} ; and Employ the following controls to achieve the denial-of-service objective: {{ insert: param, sc-05_odp.03 }}.
Last updated: 20 August 2026 13:14 UTC
Implementations targeting this control (1)
- aws-config-guardduty-enabled-centralized Guardduty Enabled Centralized AWS::GuardDuty::Detector partial detect enforce
ATT&CK techniques this control mitigates (1)
- T1496.003 SMS Pumping Impact
Weaknesses this control addresses (8)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-400 | Uncontrolled Resource Consumption | 3,800+ | Directly limits uncontrolled resource consumption that leads to denial-of-service. |
CWE-770 | Allocation of Resources Without Limits or Throttling | 2,400+ | Requires throttling and limits on resource allocation to prevent exhaustion. |
CWE-835 | Loop with Unreachable Exit Condition ('Infinite Loop') | 1,000+ | Detects and mitigates infinite loops that produce sustained resource consumption. |
CWE-674 | Uncontrolled Recursion | 500+ | Prevents uncontrolled recursion that exhausts stack or CPU resources. |
CWE-407 | Inefficient Algorithmic Complexity | 100+ | Addresses inefficient algorithms whose complexity can be exploited for DoS. |
CWE-409 | Improper Handling of Highly Compressed Data (Data Amplification) | 100+ | Limits effects of data amplification from compressed or malicious inputs. |
CWE-405 | Asymmetric Resource Consumption (Amplification) | 51 | Employs controls that mitigate amplification attacks causing asymmetric resource use. |
CWE-406 | Insufficient Control of Network Message Volume (Network Amplification) | 19 | Implements network message volume controls to block amplification DoS vectors. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2026-28318 KEV UPD | 8.5 | 7.5 | 0.0835 | good |
CVE-2023-50868 UPD | 8.4 | 7.5 | 0.8173 | good |
CVE-2024-26212 UPD | 8.2 | 7.5 | 0.6258 | good |
CVE-2026-49160 UPD | 8.0 | 7.5 | 0.5383 | good |
CVE-2024-5011 UPD | 7.8 | 7.5 | 0.4709 | good |
CVE-2024-6036 UPD | 7.8 | 9.1 | 0.1094 | good |
CVE-2025-24190 UPD | 7.6 | 9.8 | 0.0177 | good |
CVE-2025-24211 UPD | 7.6 | 9.8 | 0.0177 | good |
CVE-2024-45166 UPD | 7.5 | 9.8 | 0.0105 | good |
CVE-2025-24247 UPD | 7.5 | 9.8 | 0.0090 | good |
CVE-2025-24264 UPD | 7.5 | 9.8 | 0.0086 | good |
CVE-2026-45498 KEV UPD | 7.5 | 4.0 | 0.6308 | good |
CVE-2024-39462 UPD | 7.4 | 9.8 | 0.0077 | good |
CVE-2025-24260 UPD | 7.4 | 9.8 | 0.0084 | good |
CVE-2025-24269 UPD | 7.4 | 9.8 | 0.0074 | good |
CVE-2025-43193 UPD | 7.4 | 9.8 | 0.0074 | good |
CVE-2024-36543 UPD | 7.3 | 9.8 | 0.0052 | good |
CVE-2025-53633 UPD | 7.3 | 9.8 | 0.0046 | good |
CVE-2025-61303 UPD | 7.3 | 9.8 | 0.0043 | good |
CVE-2026-0599 UPD | 7.2 | 7.5 | 0.2249 | good |
CVE-2026-34648 UPD | 7.2 | 7.5 | 0.2255 | good |
CVE-2024-25617 UPD | 7.1 | 5.3 | 0.8886 | good |
CVE-2024-45163 UPD | 7.0 | 9.1 | 0.0077 | good |
CVE-2025-53722 UPD | 7.0 | 7.5 | 0.1794 | good |
CVE-2025-64388 UPD | 7.0 | 9.2 | 0.0035 | good |