Cyber Resilience

NIST 800-53 r5 · Controls catalogue · Family SI

SI-3Malicious Code Protection

Implement {{ insert: param, si-03_odp.01 }} malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code; Automatically update malicious code protection mechanisms as new releases are available in accordance with organizational configuration management policy and procedures; Configure malicious code protection mechanisms to: Perform periodic scans of the system {{ insert: param, si-03_odp.02 }} and real-time scans of files from external sources at {{ insert: param, si-03_odp.03 }} as the files are downloaded, opened, or executed in accordance with organizational policy; and {{ insert: param, si-03_odp.04 }} ; and send alert to {{ insert: param, si-03_odp.06 }} in response to malicious code detection; and Address the receipt of false positives during malicious code detection and eradication and the resulting potential impact on the availability of the system.

Last updated: 21 August 2026 07:11 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: partial · 1 mapping(s) from 1 framework(s): OWASP-Web 1 (partial)

See the full cumulative-coverage rollup →

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (224)

Weaknesses this control addresses (5)AI-assisted

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-434Unrestricted Upload of File with Dangerous Type5,100+Scans files from external sources on download/open/execute, blocking unrestricted uploads of dangerous file types.
CWE-502Deserialization of Untrusted Data3,600+Identifies and blocks malicious code introduced through deserialization of untrusted data at system boundaries.
CWE-829Inclusion of Functionality from Untrusted Control Sphere300+Detects and prevents inclusion of malicious functionality downloaded from untrusted control spheres.
CWE-494Download of Code Without Integrity Check200+Performs real-time scans of downloaded code, mitigating risks from downloads lacking integrity checks.
CWE-506Embedded Malicious Code99Directly detects and eradicates embedded malicious code at entry/exit points via periodic and real-time scans.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2025-31324 KEV 10.010.00.9951good
CVE-2025-52691 KEV 10.010.00.8546good
CVE-2024-50623 KEV 9.99.80.9861good
CVE-2024-8856 9.99.80.9380good
CVE-2024-53677 9.99.80.7820good
CVE-2026-48908 KEV 9.99.80.8813good
CVE-2026-48939 KEV 9.99.80.8250good
CVE-2026-56290 KEV 9.99.80.8325good
CVE-2026-56291 KEV 9.99.80.7607good
CVE-2025-34299 9.89.80.7267good
CVE-2023-51409 9.710.00.6308good
CVE-2024-57968 KEV 9.69.90.3228good
CVE-2026-0740 9.69.80.6290good
CVE-2025-26319 9.59.80.5587good
CVE-2024-5084 9.49.80.5065good
CVE-2024-44849 9.39.80.4629good
CVE-2025-640959.310.00.4466good
CVE-2024-42640 9.29.80.4346good
CVE-2024-48760 9.29.80.4511good
CVE-2025-7441 9.19.80.3949good
CVE-2023-38095 9.08.80.6552good
CVE-2024-6220 9.09.80.3571good
CVE-2024-9932 9.09.80.3641good
CVE-2026-38449.09.80.3651good
CVE-2024-56064 8.910.00.2999good

Other controls in family SI

SI-1 SI-10 SI-11 SI-12 SI-13 SI-14 SI-15 SI-16 SI-17 SI-18 SI-19 SI-2 SI-20 SI-21 SI-22 SI-23 SI-4 SI-5 SI-6 SI-7 SI-8 SI-9