NIST 800-53 r5 · Controls catalogue · Family SI
SI-14Non-persistence
Implement non-persistent {{ insert: param, si-14_odp.01 }} that are initiated in a known state and terminated {{ insert: param, si-14_odp.02 }}.
Last updated: 21 August 2026 14:15 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (7)
- T1505 Server Software Component Persistence
- T1505.001 SQL Stored Procedures Persistence
- T1505.002 Transport Agent Persistence
- T1505.004 IIS Components Persistence
- T1546.003 Windows Management Instrumentation Event Subscription Privilege Escalation, Persistence
- T1547.004 Winlogon Helper DLL Persistence, Privilege Escalation
- T1547.006 Kernel Modules and Extensions Persistence, Privilege Escalation
Weaknesses this control addresses (6)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-613 | Insufficient Session Expiration | 600+ | When the non-persistent artifact is a session or connection, mandatory termination implements the missing expiration that CWE-613 describes. |
CWE-665 | Improper Initialization | 400+ | Mandates that every instance begins in a known (presumably clean) state, eliminating reliance on residual or uninitialized state left by prior executions. |
CWE-459 | Incomplete Cleanup | 200+ | Termination of the non-persistent artifact guarantees cleanup of temporary state, directly countering incomplete cleanup weaknesses. |
CWE-506 | Embedded Malicious Code | 99 | Any embedded malicious code or backdoor written into an instance is erased at termination, rendering persistence mechanisms ineffective across successive instances. |
CWE-912 | Hidden Functionality | 87 | Hidden or unauthorized functionality introduced at runtime cannot survive instance termination, neutralizing the value of such concealed code. |
CWE-664 | Improper Control of a Resource Through its Lifetime | 47 | Directly enforces limited resource lifetime by requiring initiation from a known state and explicit termination, shrinking the window any long-lived resource weakness can be exploited. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2025-31650 UPD | 8.1 | 7.5 | 0.5992 | good |
CVE-2025-6338 UPD | 7.0 | 9.2 | 0.0040 | good |
CVE-2024-28265 UPD | 6.9 | 9.1 | 0.0046 | good |
CVE-2026-34263 UPD | 6.8 | 9.6 | 0.0061 | good |
CVE-2025-66675 | 6.3 | 8.2 | 0.0059 | good |
CVE-2025-64775 UPD | 6.1 | 7.5 | 0.0149 | good |
CVE-2025-0726 UPD | 6.0 | 7.5 | 0.0073 | good |
CVE-2025-2260 UPD | 6.0 | 7.5 | 0.0091 | good |
CVE-2021-47178 UPD | 5.9 | 7.5 | 0.0058 | good |
CVE-2026-3304 UPD | 5.9 | 7.5 | 0.0066 | good |
CVE-2026-11576 UPD | 5.9 | 7.5 | 0.0046 | good |
CVE-2026-42492 | 5.9 | 7.5 | 0.0048 | good |
CVE-2025-59781 UPD | 5.8 | 7.5 | 0.0032 | good |
CVE-2024-47674 UPD | 5.7 | 7.8 | 0.0025 | good |
CVE-2024-57975 UPD | 5.7 | 7.8 | 0.0021 | good |
CVE-2024-57976 UPD | 5.7 | 7.8 | 0.0022 | good |
CVE-2025-21924 UPD | 5.7 | 7.8 | 0.0020 | good |
CVE-2025-37908 UPD | 5.7 | 7.8 | 0.0020 | good |
CVE-2025-60730 UPD | 5.7 | 7.6 | 0.0027 | good |
CVE-2025-38177 UPD | 5.6 | 7.8 | 0.0016 | good |
CVE-2025-66467 UPD | 5.6 | 8.0 | 0.0037 | good |
CVE-2026-7639 UPD | 5.6 | 7.8 | 0.0012 | good |
CVE-2025-43711 UPD | 5.5 | 8.1 | 0.0015 | good |
CVE-2026-52736 | 5.5 | 8.7 | 0.0044 | good |
CVE-2024-23672 UPD | 5.4 | 6.3 | 0.0231 | good |