NIST 800-53 r5 · Controls catalogue · Family SR
SR-9Tamper Resistance and Detection
Implement a tamper protection program for the system, system component, or system service.
Last updated: 22 August 2026 14:14 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (0)
- No ATT&CK techniques mapped to this control yet.
Weaknesses this control addresses (7)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-284 | Improper Access Control | 6,900+ | Tamper protection directly detects and resists unauthorized modifications that improper access control would otherwise permit. |
CWE-732 | Incorrect Permission Assignment for Critical Resource | 1,900+ | Provides detection and resistance layers that reduce exploitability of incorrect critical-resource permissions. |
CWE-345 | Insufficient Verification of Data Authenticity | 800+ | The control implements verification mechanisms that detect tampering by ensuring data authenticity. |
CWE-494 | Download of Code Without Integrity Check | 200+ | Mandates integrity verification on system components, closing the gap that allows download without checks. |
CWE-354 | Improper Validation of Integrity Check Value | 200+ | Requires proper validation of integrity mechanisms, directly mitigating flawed check-value handling. |
CWE-506 | Embedded Malicious Code | 99 | Tamper detection mechanisms can identify embedded malicious code inserted via supply-chain or runtime tampering. |
CWE-353 | Missing Support for Integrity Check | 44 | Tamper protection programs explicitly add integrity checks where support was previously missing. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2025-8028 UPD | 7.3 | 9.8 | 0.0047 | partial |
CVE-2025-1566 UPD | 5.6 | 7.5 | 0.0019 | good |
CVE-2025-54520 UPD | 5.5 | 8.6 | 0.0018 | good |
CVE-2024-20059 UPD | 4.8 | 6.7 | 0.0009 | partial |
CVE-2024-4760 UPD | 4.7 | 6.3 | 0.0021 | good |
CVE-2024-20060 UPD | 4.4 | 5.9 | 0.0011 | partial |
CVE-2024-31510 UPD | 7.4 | 9.8 | 0.0062 | good |
CVE-2023-5138 UPD | 5.1 | 6.8 | 0.0027 | good |
CVE-2026-36027 | 5.1 | 6.8 | 0.0033 | partial |
CVE-2024-3094 UPD | 10.0 | 10.0 | 0.8597 | good |
CVE-2025-59374 KEV | 9.9 | 9.8 | 0.0117 | good |
CVE-2026-8398 KEV UPD | 9.9 | 9.8 | 0.0146 | good |
CVE-2026-48027 KEV UPD | 9.9 | 9.8 | 0.0185 | good |
CVE-2026-45321 KEV UPD | 9.4 | 9.6 | 0.0234 | good |
CVE-2026-33634 KEV | 9.2 | 8.8 | 0.5916 | good |
CVE-2025-30066 KEV UPD | 8.8 | 8.6 | 0.6979 | good |
CVE-2025-30154 KEV UPD | 8.8 | 8.6 | 0.0239 | good |
CVE-2024-4978 KEV UPD | 8.6 | 8.4 | 0.2694 | good |
CVE-2025-54313 KEV UPD | 8.1 | 7.5 | 0.0415 | good |
CVE-2026-46412 | 7.4 | 10.0 | 0.0042 | good |
CVE-2026-18072 | 7.4 | 9.8 | 0.0059 | good |
CVE-2026-66747 | 7.4 | 9.8 | 0.0058 | good |
CVE-2026-31976 | 7.3 | 9.8 | 0.0050 | good |
CVE-2026-34424 | 7.3 | 9.8 | 0.0055 | good |
CVE-2026-6443 | 7.3 | 9.8 | 0.0050 | good |