NIST 800-53 r5 · Controls catalogue · Family SI
SI-17Fail-safe Procedures
Implement the indicated fail-safe procedures when the indicated failures occur: {{ insert: param, si-17_prm_1 }}.
Last updated: 20 August 2026 13:14 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (0)
- No ATT&CK techniques mapped to this control yet.
Weaknesses this control addresses (8)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-404 | Improper Resource Shutdown or Release | 800+ | Procedures can mandate orderly shutdown or release of resources when failures occur, preventing improper resource handling after a fault. |
CWE-209 | Generation of Error Message Containing Sensitive Information | 600+ | Fail-safe procedures can be defined to suppress or sanitize error output, reducing generation of messages that contain sensitive information. |
CWE-755 | Improper Handling of Exceptional Conditions | 600+ | Mandates defined procedures that ensure exceptional conditions are handled in a controlled, secure manner instead of being ignored or mishandled. |
CWE-248 | Uncaught Exception | 200+ | Requires pre-defined safe responses for uncaught exceptions so they do not result in undefined or insecure program termination. |
CWE-459 | Incomplete Cleanup | 200+ | Fail-safe procedures can explicitly require cleanup of temporary state, resources, or privileges on failure to avoid leaving the system in an inconsistent state. |
CWE-703 | Improper Check or Handling of Exceptional Conditions | 100+ | Requires explicit, safe handling actions for specified exceptional conditions rather than allowing unchecked propagation or default unsafe behavior. |
CWE-636 | Not Failing Securely ('Failing Open') | 46 | Directly implements fail-safe (fail-closed/secure) behavior on indicated failures, preventing the system from defaulting to an insecure open state. |
CWE-390 | Detection of Error Condition Without Action | 20 | Ensures that detected error conditions trigger the specified safe procedures instead of being observed without corrective action. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2024-29748 KEV UPD | 8.5 | 7.8 | 0.0068 | good |
CVE-2025-10156 UPD | 7.6 | 9.8 | 0.0148 | good |
CVE-2024-21907 UPD | 7.5 | 7.5 | 0.3291 | good |
CVE-2021-42141 UPD | 7.5 | 9.8 | 0.0118 | good |
CVE-2024-43532 UPD | 7.5 | 8.8 | 0.1197 | good |
CVE-2024-26584 UPD | 7.4 | 9.8 | 0.0075 | good |
CVE-2024-3729 UPD | 7.4 | 9.8 | 0.0081 | good |
CVE-2026-22034 UPD | 7.4 | 9.8 | 0.0067 | good |
CVE-2022-48673 UPD | 7.3 | 9.8 | 0.0050 | good |
CVE-2025-13021 UPD | 7.2 | 9.8 | 0.0036 | good |
CVE-2025-13022 UPD | 7.2 | 9.8 | 0.0036 | good |
CVE-2025-13023 UPD | 7.2 | 9.8 | 0.0036 | good |
CVE-2025-13026 UPD | 7.2 | 9.8 | 0.0036 | good |
CVE-2025-43864 UPD | 7.1 | 7.5 | 0.2021 | good |
CVE-2023-45927 UPD | 7.0 | 9.1 | 0.0084 | good |
CVE-2026-40525 UPD | 6.9 | 9.1 | 0.0057 | good |
CVE-2023-6267 UPD | 6.7 | 8.6 | 0.0072 | good |
CVE-2024-3150 UPD | 6.7 | 8.8 | 0.0079 | good |
CVE-2024-10781 UPD | 6.7 | 8.1 | 0.0379 | good |
CVE-2025-59538 | 6.7 | 7.5 | 0.0834 | good |
CVE-2026-27586 | 6.7 | 9.1 | 0.0027 | good |
CVE-2024-7521 | 6.6 | 8.8 | 0.0062 | good |
CVE-2026-40371 UPD | 6.6 | 8.8 | 0.0063 | good |
CVE-2026-68746 | 6.6 | 8.8 | 0.0045 | good |
CVE-2024-39815 UPD | 6.5 | 9.1 | 0.0077 | good |