Cyber Resilience

NIST 800-53 r5 · Controls catalogue · Family SC

SC-5Denial-of-service Protection

{{ insert: param, sc-05_odp.02 }} the effects of the following types of denial-of-service events: {{ insert: param, sc-05_odp.01 }} ; and Employ the following controls to achieve the denial-of-service objective: {{ insert: param, sc-05_odp.03 }}.

Last updated: 20 August 2026 13:14 UTC

Implementations targeting this control (1)

ATT&CK techniques this control mitigates (1)

Weaknesses this control addresses (8)AI-assisted

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-400Uncontrolled Resource Consumption3,800+Directly limits uncontrolled resource consumption that leads to denial-of-service.
CWE-770Allocation of Resources Without Limits or Throttling2,400+Requires throttling and limits on resource allocation to prevent exhaustion.
CWE-835Loop with Unreachable Exit Condition ('Infinite Loop')1,000+Detects and mitigates infinite loops that produce sustained resource consumption.
CWE-674Uncontrolled Recursion500+Prevents uncontrolled recursion that exhausts stack or CPU resources.
CWE-407Inefficient Algorithmic Complexity100+Addresses inefficient algorithms whose complexity can be exploited for DoS.
CWE-409Improper Handling of Highly Compressed Data (Data Amplification)100+Limits effects of data amplification from compressed or malicious inputs.
CWE-405Asymmetric Resource Consumption (Amplification)51Employs controls that mitigate amplification attacks causing asymmetric resource use.
CWE-406Insufficient Control of Network Message Volume (Network Amplification)19Implements network message volume controls to block amplification DoS vectors.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2026-28318 KEV 8.57.50.0835good
CVE-2023-50868 8.47.50.8173good
CVE-2024-26212 8.27.50.6258good
CVE-2026-49160 8.07.50.5383good
CVE-2024-5011 7.87.50.4709good
CVE-2024-6036 7.89.10.1094good
CVE-2025-24190 7.69.80.0177good
CVE-2025-24211 7.69.80.0177good
CVE-2024-45166 7.59.80.0105good
CVE-2025-24247 7.59.80.0090good
CVE-2025-24264 7.59.80.0086good
CVE-2026-45498 KEV 7.54.00.6308good
CVE-2024-39462 7.49.80.0077good
CVE-2025-24260 7.49.80.0084good
CVE-2025-24269 7.49.80.0074good
CVE-2025-43193 7.49.80.0074good
CVE-2024-36543 7.39.80.0052good
CVE-2025-53633 7.39.80.0046good
CVE-2025-61303 7.39.80.0043good
CVE-2026-0599 7.27.50.2249good
CVE-2026-34648 7.27.50.2255good
CVE-2024-25617 7.15.30.8886good
CVE-2024-45163 7.09.10.0077good
CVE-2025-53722 7.07.50.1794good
CVE-2025-64388 7.09.20.0035good

Other controls in family SC

SC-1 SC-10 SC-11 SC-12 SC-13 SC-14 SC-15 SC-16 SC-17 SC-18 SC-19 SC-2 SC-20 SC-21 SC-22 SC-23 SC-24 SC-25 SC-26 SC-27 SC-28 SC-29 SC-3 SC-30 SC-31 SC-32 SC-33 SC-34 SC-35 SC-36 SC-37 SC-38 SC-39 SC-4 SC-40 SC-41 SC-42 SC-43 SC-44 SC-45 SC-46 SC-47 SC-48 SC-49 SC-50 SC-51 SC-6 SC-7 SC-8 SC-9