Cyber Resilience

NIST 800-53 r5 · Controls catalogue · Family SI

SI-17Fail-safe Procedures

Implement the indicated fail-safe procedures when the indicated failures occur: {{ insert: param, si-17_prm_1 }}.

Last updated: 20 August 2026 13:14 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (0)

Weaknesses this control addresses (8)AI-assisted

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-404Improper Resource Shutdown or Release800+Procedures can mandate orderly shutdown or release of resources when failures occur, preventing improper resource handling after a fault.
CWE-209Generation of Error Message Containing Sensitive Information600+Fail-safe procedures can be defined to suppress or sanitize error output, reducing generation of messages that contain sensitive information.
CWE-755Improper Handling of Exceptional Conditions600+Mandates defined procedures that ensure exceptional conditions are handled in a controlled, secure manner instead of being ignored or mishandled.
CWE-248Uncaught Exception200+Requires pre-defined safe responses for uncaught exceptions so they do not result in undefined or insecure program termination.
CWE-459Incomplete Cleanup200+Fail-safe procedures can explicitly require cleanup of temporary state, resources, or privileges on failure to avoid leaving the system in an inconsistent state.
CWE-703Improper Check or Handling of Exceptional Conditions100+Requires explicit, safe handling actions for specified exceptional conditions rather than allowing unchecked propagation or default unsafe behavior.
CWE-636Not Failing Securely ('Failing Open')46Directly implements fail-safe (fail-closed/secure) behavior on indicated failures, preventing the system from defaulting to an insecure open state.
CWE-390Detection of Error Condition Without Action20Ensures that detected error conditions trigger the specified safe procedures instead of being observed without corrective action.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2024-29748 KEV 8.57.80.0068good
CVE-2025-10156 7.69.80.0148good
CVE-2024-21907 7.57.50.3291good
CVE-2021-42141 7.59.80.0118good
CVE-2024-43532 7.58.80.1197good
CVE-2024-26584 7.49.80.0075good
CVE-2024-3729 7.49.80.0081good
CVE-2026-22034 7.49.80.0067good
CVE-2022-48673 7.39.80.0050good
CVE-2025-13021 7.29.80.0036good
CVE-2025-13022 7.29.80.0036good
CVE-2025-13023 7.29.80.0036good
CVE-2025-13026 7.29.80.0036good
CVE-2025-43864 7.17.50.2021good
CVE-2023-45927 7.09.10.0084good
CVE-2026-40525 6.99.10.0057good
CVE-2023-6267 6.78.60.0072good
CVE-2024-3150 6.78.80.0079good
CVE-2024-10781 6.78.10.0379good
CVE-2025-595386.77.50.0834good
CVE-2026-275866.79.10.0027good
CVE-2024-75216.68.80.0062good
CVE-2026-40371 6.68.80.0063good
CVE-2026-687466.68.80.0045good
CVE-2024-39815 6.59.10.0077good

Other controls in family SI

SI-1 SI-10 SI-11 SI-12 SI-13 SI-14 SI-15 SI-16 SI-18 SI-19 SI-2 SI-20 SI-21 SI-22 SI-23 SI-3 SI-4 SI-5 SI-6 SI-7 SI-8 SI-9