NIST 800-53 r5 · Controls catalogue · Family SR
SR-10Inspection of Systems or Components
Inspect the following systems or system components {{ insert: param, sr-10_odp.02 }} to detect tampering: {{ insert: param, sr-10_odp.01 }}.
Last updated: 21 August 2026 07:11 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (0)
- No ATT&CK techniques mapped to this control yet.
Weaknesses this control addresses (7)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-829 | Inclusion of Functionality from Untrusted Control Sphere | 300+ | Inspection can detect malicious functionality that was included from an untrusted sphere through tampering or supply-chain attack. |
CWE-494 | Download of Code Without Integrity Check | 200+ | Post-download inspection serves as a compensating control that detects code tampering when integrity checks were not performed at acquisition time. |
CWE-506 | Embedded Malicious Code | 99 | Direct inspection of components can detect embedded malicious code inserted through supply-chain or runtime tampering. |
CWE-912 | Hidden Functionality | 87 | Inspection can reveal hidden functionality that an attacker has introduced via tampering or unauthorized modification. |
CWE-1191 | On-Chip Debug and Test Interface With Improper Access Control | 22 | Inspection of on-chip debug/test interfaces can identify tampering or unauthorized access that those interfaces enable. |
CWE-1242 | Inclusion of Undocumented Features or Chicken Bits | 14 | Inspection can uncover undocumented features or chicken bits that result from tampering or malicious insertion. |
CWE-1263 | Improper Physical Access Control | 13 | Physical inspection directly detects tampering that occurs when physical access controls are absent or bypassed. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
| No CVEs annotated to this control yet — the per-CVE backfill is in progress. | ||||