A.5.29 Organizational
Information security during disruption
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (17)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CP-10mostlyaligns with — Both emphasize restoring the security posture of information and supporting systems to a defined level within required time frames after a disruption.
- CP-2mostlyaligns with — Both controls require the development and maintenance of documented plans that preserve security objectives when normal operations are interrupted.
- CP-2mostlycovers — A.5.29's explicit focus on protecting information/assets during disruption directly accounts for the core of CP-2's requirements around maintaining essential functions and recovery during system disruption, but leaves some residual (e.g., detailed metrics, contact lists, and full plan development mechanics) uncovered.
- CP-4partialaligns with — Both require testing of continuity arrangements to verify that security controls remain effective or can be restored after an interruption.
- CP-7partialaligns with — Both address the need to sustain or re-establish security controls at an alternate processing site when primary operations are disrupted.
- CP-7partialcovers — A.5.29's broad requirement to protect information/assets during any disruption is substantially addressed by CP-7's specific alternate-site capability for essential functions, but leaves residual aspects (e.g. non-IT assets, non-processing disruptions, or pre-transfer protection) uncovered.
- IR-4partialaligns with — Both require the organization to maintain or restore security controls as part of handling incidents that interrupt normal operations.
- CP-10covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- CP-4covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Aligned NIST CSF 2.0 outcomes (15)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- ID.IM-04mostlyaligns with — By mandating that information security requirements be integrated into business continuity processes and that plans be developed, tested, reviewed, and evaluated, the ISO control fulfills the CSF outcome of establishing, communicating, maintaining, and testing incident response and other cybersecurity plans that affect operations.
- PR.IR-03mostlyaligns with — The ISO control requires embedding information security controls into business continuity and ICT continuity plans so that security is maintained or restored during disruption, which directly supports the CSF outcome of implementing mechanisms to achieve resilience requirements in both normal and adverse situations.
- GV.SC-08partialaligns with — The ISO control’s emphasis on maintaining or restoring security of information for critical business processes during disruption supports the CSF outcome of including relevant suppliers and third parties in incident planning, response, and recovery activities.
- RC.RP-01partialaligns with — The ISO control’s requirement to restore information security at the required level and within defined time frames after an interruption aligns with the CSF outcome of executing the recovery portion of the incident response plan once initiated.
- RC.RP-04partialaligns with — Including information security controls in business continuity plans ensures that critical mission functions and cybersecurity risk management are considered when establishing post-incident operational norms, matching the CSF outcome.
- GV.SC-08implements — Assessed as NOT holding by the authoring instrument at v1.19-2026-08-23. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- ID.IM-04implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.IR-03implements — A.5.29 operationalizes resilience mechanisms for information/assets in adverse situations, which directly sits inside the PR.IR-03 outcome's domain without the CSF row explicitly naming the ISO control
- RC.RP-01implements — A.5.29's operational requirement to protect assets during disruption directly gives effect to executing the recovery portion of the IR plan (RC.RP-01) as the technical means within the recovery domain
- RC.RP-04implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Related OWASP ASVS 5.0 requirements (5)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (5)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-770nonemitigates — Mandating tested continuity procedures that preserve or replace resource-limiting controls prevents an attacker from exploiting the absence of throttling mechanisms during an outage.
- CWE-1384mitigates — Ensures information security is maintained during physical or environmental disruptions.
- CWE-284mitigates — By requiring compensating controls and restoration of security mechanisms during disruption, the control limits the window in which an attacker can exploit missing or degraded access-control enforcement.
- CWE-400mitigates — Business-continuity plans that include resource-management controls reduce the likelihood that an attacker can trigger uncontrolled resource consumption by forcing the system into a degraded or fallback state.
Mitigated MITRE ATT&CK techniques (434)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1003.003prevents — A.5.29 requires determining, including in BCM, and maintaining/restoring information security controls (including compensating ones) during disruption; this constrains the backup-search slice of T1003.003 (which explicitly targets backups created or exposed by disruption events) but leaves the live-DC extraction techniques untouched.
- T1003.003recovers — A.5.29 explicitly requires plans, controls, and compensating measures to restore the security of information (and associated assets) to the required level within required time frames after interruption or failure, which directly recovers from the post-exfiltration state created by T1003.003 (stolen NTDS.dit/credential data and derived access rights).
- T1003.005prevents — A.5.29 requires determining, planning, implementing, testing, and maintaining information security controls (including compensating ones) during disruption to protect assets; cached domain credentials exist precisely to enable authentication *during* domain-controller unavailability (a canonical disruption), so the control's mandate to adapt/compensate reaches and constrains this technique in the disruption lane, but only partially because the clause is high-level governance that does not dictate any concrete mechanism (e.g., disabling caching, encrypting the cache, or limiting its exposure).
- T1037.004prevents — A.5.29 requires determining security requirements, including them in BCM processes, and maintaining/implementing compensating controls during disruption (including post-interruption recovery of critical processes), which can prevent RC script abuse as a persistence vector in reboot/disruption scenarios on affected platforms, but only for a minority slice of the technique's scope (lightweight/embedded systems where it is one of few persistence options, and not the dominant modern use on systemd-based Linux/macOS).
- T1052prevents — A.5.29 requires determining, planning, implementing, testing, and maintaining adapted/compensating information security controls (including physical-medium protections) inside BCM and ICT continuity processes so the exfiltration technique cannot succeed during a disruption; this reaches the air-gapped/physical-removable slice of T1052 but leaves the non-disruption case and many implementation gaps untouched.
- T1055.003detects — A.5.29 requires information security controls, tools, and processes (including in continuity plans) that can surface anomalies or maintain detection during disruption, but does not mandate or address specific detection of in-process thread hijacking techniques.
- T1055.013detects — A.5.29 requires information security controls and processes (including monitoring implied by continuity plans and compensating controls) to be maintained or adapted during disruption, which can surface anomalous process execution like doppelgänging as part of restored or adapted detection, but only as a minority slice of the technique's core evasion mechanism rather than dedicated detection.
- T1074recovers — A.5.29 explicitly requires plans, controls and compensating measures to restore the security of information (and associated assets) of critical business processes following interruption or failure, which directly matches the `recovers` verb for a post-staging state where data has already been touched by the adversary.
- T1110.001prevents — A.5.29 requires determining, planning, implementing, testing and maintaining adapted/compensating information security controls (including auth-related ones) inside BCM and ICT continuity plans so that guessing attacks cannot succeed during a disruption; this directly stops the technique in the named continuity context, with a bounded remainder for non-disruption periods and non-adapted controls.
- T1127.002recovers — A.5.29 explicitly requires plans, controls, and compensating measures to maintain or restore the security of information and assets following interruption or failure, which directly enacts recovery of the protected state after a T1127.002 abuse has occurred.
- T1137.001prevents — A.5.29 requires determining, planning, implementing, testing and maintaining adapted/compensating information security controls (including macro-related ones) inside BCM and ICT continuity plans so the technique cannot succeed during disruption; this reaches only the disruption slice of the persistence technique, leaving normal-operation abuse untouched.
- T1137.002prevents — A.5.29 requires determining, planning, implementing, testing and maintaining adapted/compensating information security controls (including within continuity plans) that can explicitly block or constrain the Office Test registry abuse during a disruption, but this is a minority slice of the technique's attack surface which occurs in normal non-disrupted operations.
- T1137.003prevents — A.5.29 requires determining, planning, implementing, testing and maintaining adapted/compensating information security controls (including within business continuity and ICT continuity plans) that can explicitly constrain or block the addition and loading of malicious Outlook forms during a disruption, but this is only a slice of the technique's attack surface which lives primarily in normal operations outside disruption events.
- T1137.004prevents — A.5.29 requires determining, planning, implementing, testing and maintaining adapted/compensating information security controls (including within continuity plans) that can explicitly block or constrain the post-disruption execution path of a malicious Outlook Home Page, but the clause stops at mandating the existence of such plans and compensating controls rather than guaranteeing their completeness or enforcement against this specific legacy persistence vector.
- T1137.005detects — A.5.29 requires plans, testing, and compensating controls that can include monitoring for anomalous rule behavior or execution during disruption, but this is indirect, scope-limited by business continuity requirements, and does not mandate detection of the technique itself.
- T1137.005prevents — A.5.29 requires determining, planning, implementing, testing and maintaining adapted/compensating information security controls (including in BCM and ICT continuity plans) that can explicitly constrain or block the execution path of a persistence technique such as malicious Outlook rules during a disruption; this reaches part of the class but leaves the pre-disruption compromise vector and non-disruption scenarios untouched.
- T1207recovers — A.5.29 explicitly plans, tests and restores the security of information (and associated assets) to the required level after interruption or failure, which matches the post-impact recovery of AD integrity, objects, credentials and metadata altered by a rogue DC.
- T1213prevents — A.5.29 requires determining, planning, implementing, testing, and maintaining adapted/compensating information security controls (including access-oriented ones) during disruption, which can stop the technique from succeeding when a disruption creates or widens repository exposure vectors; this is only a slice of the class because the control is scoped exclusively to disruption events and does not address the technique's normal-operation root causes (e.g., misconfigured sharing or overly-broad access in stable environments).
- T1213recovers — A.5.29 explicitly requires plans to maintain or restore the security of information of critical business processes following interruption or failure, directly addressing recovery of protected state after a disruption that enables T1213 (e.g., via lost controls leading to exposed repositories).
- T1218.004detects — A.5.29 requires plans, testing, and compensating controls that can include monitoring/detection mechanisms within continuity processes, but does not mandate or focus on detecting the specific InstallUtil proxy execution technique itself.
- T1218.005detects — A.5.29 requires information security controls and processes (including monitoring) to be maintained or adapted within business continuity plans during disruption, which can surface anomalous use of mshta.exe as part of restored or compensating controls, but only as a minority slice of general detection rather than a dedicated or comprehensive capability against this technique.
- T1218.008detects — A.5.29 requires monitoring and testing of continuity plans that include information security controls and compensating controls, which can surface anomalous use of signed binaries like odbcconf.exe during a disruption but does not mandate or focus on detection of this specific technique.
- T1218.009detects — A.5.29 requires information security controls, monitoring processes, and compensating controls to be maintained and adapted during disruption, which can surface anomalous use of signed binaries like Regsvcs/Regasm as part of continuity monitoring, but does not mandate or focus on technique-specific detection of proxy execution or LOLBAS abuse.
- T1219responds — A.5.29 explicitly requires plans that maintain/restore security during disruption, implement compensating controls when primary ones cannot be maintained, and integrate security into business continuity and ICT continuity processes; these directly engage once an adversary has established a RAT C2 channel (the technique is already running) by containing its impact, enabling eradication through restored controls, and bounding further spread during the incident.
- T1485prevents — A.5.29 requires determining, planning, implementing, testing, and maintaining information security controls (including compensating ones) within business continuity and ICT continuity processes specifically to protect information assets and restore their security during/after disruption, which directly constrains the availability-interruption goal of T1485 data destruction in critical processes.
- T1485recovers — A.5.29 explicitly requires plans, controls, and compensating measures to maintain or restore the security (including availability) of information and critical processes following interruption or failure, which directly matches recovering from the availability loss caused by T1485 data destruction.
- T1485responds — A.5.29 explicitly requires plans, controls, compensating measures and restoration processes that activate once disruption (including data-destruction events) is underway, performing the containment/eradication/restoration acts that `responds` names; the named remainder is that it is a planning-level control whose technical execution lives in linked BCM/ICT plans rather than inside A.5.29 itself.
- T1485.001recovers — A.5.29 explicitly requires plans, controls, and compensating measures to maintain/restore information security (and the information itself) of critical processes following interruption or failure, which directly addresses recovery from the data destruction performed by this technique.
- T1486detects — A.5.29 requires determining, planning, implementing, testing and maintaining information security controls (including compensating ones) inside business continuity and ICT continuity plans so that security can be maintained or restored after interruption; this surfaces gaps or failures in those controls during a disruption event such as ransomware encryption, but only for the continuity-slice of the technique and only after impact has begun.
- T1486prevents — A.5.29 explicitly requires plans, maintained/compensating controls, and restoration of security within time frames during disruption; this directly constrains ransomware encryption (T1486) from succeeding in its availability-impact goal when continuity measures keep data accessible or quickly recoverable, though some residual impact window remains before restoration.
- T1486recovers — A.5.29 explicitly requires plans, controls, and compensating measures to maintain or restore the security (including availability) of information and assets following interruption or failure, directly addressing post-encryption recovery of data accessibility in continuity processes.
- T1486responds — A.5.29 explicitly requires plans, controls, compensating measures and restoration processes that activate once disruption (including ransomware encryption) is underway, directly matching the `responds` verb of containment/eradication during an active event.
- T1489prevents — A.5.29 requires determining, planning, implementing, testing, and maintaining information security controls (including compensating ones) within business continuity and ICT continuity processes to protect assets and restore security during disruption; this constrains many T1489 instances that target availability or enable follow-on impact techniques during an incident, but leaves open-ended slices such as non-disruption-motivated stops, cloud API abuse outside continuity scope, and pre-disruption execution.
- T1489recovers — A.5.29 explicitly requires plans, controls, and compensating measures to maintain or restore the security of information and assets (including services) following interruption or failure, directly addressing recovery from a service-stop technique that disrupts availability or enables further impact.
- T1489responds — A.5.29 explicitly requires plans, compensating controls, and processes to maintain/restore security of critical business processes during disruption, which directly engages incident response activities (containment via compensating controls or service recovery) once a service-stop technique is underway, but only for the business-critical subset rather than all possible services or full eradication of the actor's action.
- T1490detects — A.5.29 requires determining requirements, including security controls and processes in BCM/ICT continuity plans, and maintaining/implementing compensating controls during disruption, which can encompass monitoring and detection mechanisms for recovery-inhibiting actions as part of tested plans, but does not mandate or focus on detection itself.
- T1490recovers — A.5.29 explicitly requires plans, controls, and compensating measures to maintain/restore security of critical processes and information following interruption or failure, directly addressing recovery of recovery mechanisms that T1490 seeks to destroy.
- T1490responds — A.5.29 explicitly requires plans, compensating controls, and processes to maintain/restore security of critical information and assets once disruption (including adversary-inhibited recovery) is underway, which matches the `responds` act of containment/eradication during an active T1490 event.
- T1491recovers — A.5.29 explicitly requires plans to maintain/restore the security (including integrity) of information in critical processes following interruption or failure, and to restore it to the required level within required time frames; this directly matches recovery from a defacement that has already altered visual content.
- T1491.001detects — A.5.29 requires plans, testing, and compensating controls that include monitoring and anomaly detection during disruptions, which can surface internal defacement once it occurs as part of restoring integrity, but this is only a slice of the technique's post-intrusion execution across normal and disrupted states.
- T1491.001recovers — A.5.29 explicitly requires plans to maintain/restore the security of information (and associated assets) of critical business processes following interruption or failure, which directly matches recovery of integrity after internal defacement of systems, websites, login messages or desktops; partial because the control is scoped to critical processes/assets and does not guarantee full restoration of every possible defaced non-critical internal object.
- T1491.002recovers — A.5.29 explicitly requires plans to maintain/restore the security of information and assets (including compensating controls) following interruption or failure, which directly recovers from the integrity loss and distrust caused by external defacement.
- T1491.002responds — A.5.29 requires plans, compensating controls, and restoration of security during/after disruption; external defacement is a realized impact that can be contained, messaged around, and recovered from under BCM processes, but the clause is scoped to general disruption (not this specific technique) and does not address the propaganda or precursor aspects.
- T1495prevents — A.5.29 requires determining, planning, implementing, testing, and maintaining adapted/compensating information security controls (including within ICT continuity plans) to protect assets and restore security during disruption, which can prevent some firmware corruption techniques that rely on or exploit disrupted states, but leaves many direct overwrite vectors (e.g., via malware on live systems) unaddressed as it focuses on continuity adaptation rather than specific firmware protections.
- T1495recovers — A.5.29 explicitly requires plans, controls, and compensating measures to maintain/restore security of critical processes and information following interruption or failure, which directly addresses recovery from the availability loss and potential data destruction caused by firmware corruption.
- T1496detects — A.5.29 requires determining, implementing, and maintaining information security controls (including within continuity plans and as compensating controls) that can encompass detection mechanisms for anomalous resource usage during disruptions, but this is not a primary or mandated function of the control.
- T1496prevents — A.5.29 requires determining, planning, implementing, testing, and maintaining information security controls (including compensating ones) within business continuity and ICT continuity processes to protect assets and restore security post-disruption, which can prevent some forms of resource hijacking (e.g., by limiting compute/network abuse during outages) but leaves many execution paths (e.g., stealthy cryptomining on non-critical systems) untouched.
- T1496recovers — A.5.29 explicitly requires plans to maintain/restore security of critical processes and information post-interruption, plus compensating controls during disruption, which directly supports recovery from resource hijacking's availability impact.
- T1496responds — A.5.29 explicitly requires plans, compensating controls, and processes to maintain/restore information security (and availability) once a disruption event is underway, which directly matches the `responds` act of containment/eradication during an active resource-hijacking incident.
- T1496.001detects — A.5.29 requires plans, testing, and compensating controls that can include monitoring/detection mechanisms during disruption to identify when hijacking consumes resources and impacts availability, but this is only a slice of the technique's full pre- and post-disruption attack surface.
- T1496.001prevents — A.5.29 requires determining, planning, implementing, testing, and maintaining adapted/compensating information security controls (including within continuity and ICT continuity plans) to protect assets and maintain/restore security of critical processes during disruption, which directly constrains the availability-impact slice of compute hijacking (e.g., via resource protections or compensating measures) but leaves the initial compromise vectors, non-disruption resource theft, and many deployment paths untouched.
- T1496.001recovers — A.5.29 explicitly requires plans to maintain/restore security of critical processes following interruption or failure, and to restore information security to the required level within required time frames; this directly recovers availability degraded by compute hijacking (resource exhaustion/DoS).
- T1496.001responds — A.5.29 explicitly requires plans, compensating controls, and processes to maintain/restore security of information and assets once disruption (including resource exhaustion from hijacking) is underway, which matches the `responds` verb; extent is partial because the clause is scoped to business continuity and critical processes rather than full containment/eradication of the adversary technique itself.
- T1496.002detects — A.5.29 requires plans, testing, and compensating controls that can include monitoring/detection mechanisms to identify when a disruption (including bandwidth consumption from hijacking) is occurring so that security can be maintained or restored.
- T1496.002prevents — A.5.29 requires determining, planning, implementing, testing, and maintaining adapted/compensating information security controls (including within continuity plans) to protect assets and restore security during disruption, which can constrain or block bandwidth hijacking as a form of availability-impacting disruption in some scenarios, but only reaches a minority slice of the technique's vectors (e.g., botnets, proxyjacking, scanning) rather than the bulk.
- T1496.002recovers — A.5.29 explicitly requires plans to maintain/restore security of critical processes following interruption or failure, and to implement compensating controls during disruption, which directly addresses recovery of availability and security after bandwidth hijacking has impacted systems.
- T1496.002responds — A.5.29 explicitly requires plans, compensating controls, and processes to maintain/restore security of information and assets once disruption (including availability-impacting bandwidth consumption) is underway, which matches the `responds` act of containment/eradication during an active event.
- T1496.003detects — A.5.29 requires determining, planning, implementing, testing and maintaining information security controls (including compensating ones) during disruption, which can encompass detection mechanisms for anomalous SMS traffic or overwhelmed channels as part of continuity response, but the control's focus is on requirements and planning rather than mandating specific detection of the T1496.003 technique.
- T1496.003prevents — A.5.29 requires determining requirements, including security controls in BCM/ICT continuity plans, maintaining existing controls or implementing compensating ones during disruption, which directly constrains the availability-impacting effects of SMS pumping (e.g., via rate limiting, input validation on OTP forms, or continuity measures for overwhelmed channels), but only addresses a minority slice since the technique primarily exploits design/implementation flaws in public web forms and messaging services rather than a post-interruption disruption event.
- T1496.003recovers — A.5.29 explicitly requires plans to maintain/restore security of critical processes following interruption or failure, and to restore information security to the required level within required time frames; this directly matches recovery from the availability/cost impact caused by SMS pumping overload.
- T1496.004prevents — A.5.29 requires determining, planning, implementing, testing, and maintaining adapted/compensating information security controls (including within continuity plans) to protect assets and restore security during disruption, which can constrain or block some hijacking vectors (e.g., via maintained access controls, quota enforcement, or compensating measures on critical SaaS), but leaves open-ended residual paths such as initial compromise, enabling unused services, or unaddressed LLMJacking that the control does not universally stop.
- T1496.004recovers — A.5.29 explicitly requires plans to maintain/restore security of critical processes following interruption or failure, and to restore information security to the required level within required time frames; the technique's core impact is service unavailability, quota exhaustion and financial cost from resource abuse, which continuity plans directly address by restoring availability.
- T1498detects — A.5.29 requires plans, testing, and compensating controls that can include detection mechanisms (e.g., monitoring for anomalous traffic volumes during disruption) to identify when a DoS is occurring and trigger response, but this is only a minority slice of the control's focus on continuity planning rather than dedicated detection.
- T1498prevents — A.5.29 requires determining, planning, implementing, testing, and maintaining adapted/compensating information security controls (including within continuity plans) to protect information assets and restore security post-disruption, which can prevent some T1498 impacts on critical services but leaves open-ended residual where bandwidth exhaustion or volumetric flooding succeeds before or despite the adapted controls.
- T1498recovers — A.5.29 explicitly requires plans, controls, and compensating measures to restore the security of information and critical processes (including availability) within required time frames after interruption or failure, which directly matches recovery from a Network DoS impact.
- T1498responds — A.5.29 explicitly requires plans that are implemented/tested to maintain/restore security of critical processes during interruption or failure, plus compensating controls when primary ones cannot be maintained — this directly matches the `responds` verb of acting on an event once underway to contain/eradicate its effects (here, a DoS disrupting availability).
- T1498.001detects — A.5.29 requires determining, planning, implementing, testing and maintaining information security controls (including monitoring/detection capabilities) within business continuity and ICT continuity plans to protect assets and restore security during disruption; this surfaces the flood's impact on availability as an incident but only as a bounded slice of the full technique (no mandate for real-time traffic analysis, anomaly detection at scale, or distinguishing DDoS from legitimate load).
- T1498.001prevents — A.5.29 requires determining, planning, implementing, testing, and maintaining adapted/compensating information security controls (including within continuity plans) to protect assets and restore security during disruption, which can prevent a direct network flood from fully realizing its impact on critical business processes by enabling continuity measures that sustain availability.
- T1498.001recovers — A.5.29 explicitly requires plans, controls, and compensating measures to restore the security of information and critical processes following interruption or failure, which directly addresses recovery from the availability loss inflicted by a direct network flood (T1498.001).
- T1498.001responds — A.5.29 explicitly requires plans, compensating controls, and restoration processes that activate once disruption (including a network flood DoS) is underway, performing containment/eradication/restoration of security per the event-lane definition of responds.
- T1498.002detects — A.5.29 requires information security controls (including monitoring/detection capabilities) to be maintained or adapted inside continuity plans during disruption, which can surface anomalous traffic from a reflection amplification DoS, but only as one possible compensating or restored control rather than a dedicated detection mandate.
- T1498.002prevents — A.5.29 requires determining, planning, implementing, testing, and maintaining adapted/compensating information security controls (including in BCP/ICT continuity) to protect assets and restore security during disruption; this directly constrains the availability-impact slice of a reflection-amplification DoS but leaves the pre-disruption network, protocol, and reflector-configuration vectors untouched.
- T1498.002recovers — A.5.29 explicitly requires plans, controls, and compensating measures to restore the security (including availability) of critical business processes and information within required time frames after interruption or failure, which directly matches recovery from the availability loss inflicted by a reflection amplification DoS.
- T1498.002responds — A.5.29 requires plans, controls, and compensating measures to maintain/restore security (including availability) once disruption from a reflection amplification DoS is underway, which matches the `responds` verb, but only partially because its focus is on generic business continuity rather than incident-specific containment/eradication of the attack itself.
- T1499detects — A.5.29 requires determining requirements, including in BCM processes, and developing/implementing/reviewing plans that maintain or restore security (with compensating controls) during disruption, which surfaces availability-impacting DoS events as part of continuity monitoring but only as a minority slice of the broad technique class.
- T1499prevents — A.5.29 requires determining, planning, implementing, testing, and maintaining adapted/compensating information security controls (including within continuity plans) to protect information assets and restore security during disruption, which constrains some endpoint DoS techniques that target availability of critical services but leaves many others (e.g., resource exhaustion, botnets, spoofing) unaddressed as the control is not specific to DoS prevention.
- T1499recovers — A.5.29 explicitly requires plans, controls, and compensating measures to maintain/restore security of critical processes and information following interruption or failure, which directly addresses recovery of availability after an Endpoint DoS has occurred.
- T1499responds — A.5.29 requires plans, controls, and compensating measures to maintain/restore security (including availability) of critical processes once disruption occurs, which engages the containment/eradication slice of `responds` for realized endpoint DoS but leaves the pre-impact detection and full eradication of the attack vector as a remainder
- T1499.001detects — A.5.29 requires plans, testing, and compensating controls that can include monitoring/detection mechanisms within continuity processes to identify when a disruption (such as OS resource exhaustion) is occurring, but this is indirect, governance-oriented, and not a dedicated detection capability.
- T1499.001prevents — A.5.29 requires determining, planning, implementing, testing, and maintaining adapted/compensating information security controls (including in ICT continuity plans) to protect assets and restore security during disruption, which can prevent some OS-exhaustion flood techniques from succeeding when they manifest as a disruption event, but leaves many residual cases (e.g., unmitigated network floods before detection, non-critical systems, or limits not covered by the adapted controls).
- T1499.001recovers — A.5.29 explicitly requires plans, controls, and compensating measures to maintain or restore the security of information and assets (including during/after ICT disruptions like resource-exhaustion DoS) within required time frames, which directly enacts recovery of the affected state.
- T1499.001responds — A.5.29 requires plans, processes and compensating controls that activate during disruption to maintain/restore security of critical processes; this engages the core of `responds` (containment/eradication once the OS-exhaustion flood is underway) for the bounded slice of critical-business-process systems, but leaves non-critical systems, non-ICT disruptions, and pre-disruption prevention untouched.
- T1499.002detects — A.5.29 requires plans, testing, and compensating controls that can include detection mechanisms (e.g., monitoring for exhaustion during disruption) but does not mandate or focus on detection of the T1499.002 technique itself.
- T1499.002prevents — A.5.29 requires determining, planning, implementing, testing, and maintaining adapted/compensating information security controls (including within continuity plans) to protect assets and restore security during disruption, which can prevent some service-exhaustion floods from succeeding by sustaining availability of critical services, but leaves many volumetric or protocol-specific DoS vectors (e.g., raw HTTP floods or SSL renegotiation) unaddressed as they fall outside core continuity planning.
- T1499.002recovers — A.5.29 explicitly requires plans, controls, and compensating measures to restore the security (including availability) of critical business processes and information within required time frames after interruption or failure, which directly matches recovery from a service-exhaustion DoS event.
- T1499.002responds — A.5.29 explicitly requires plans that maintain/restore security of critical processes during disruption (including compensating controls and tested continuity plans), which directly engages the core of `responds` (containment/eradication once a DoS flood is underway) for service-exhaustion events that trigger disruption.
- T1499.003detects — A.5.29 requires inclusion of information security requirements and controls (including monitoring/detection capabilities) in business continuity and ICT continuity plans, which can surface application-exhaustion DoS during a disruption but does not mandate or guarantee detection of the technique itself.
- T1499.003prevents — A.5.29 explicitly requires determining, planning, implementing, testing and maintaining information security controls (including compensating ones) within business continuity and ICT continuity plans to protect availability of critical processes during disruption, which directly constrains application-exhaustion techniques that realize DoS; partial because the clause is scoped to requirements for critical processes and does not mandate universal technical blocks on all resource-intensive features across all applications.
- T1499.003recovers — A.5.29 explicitly requires plans, controls, and compensating measures to restore the security of information and critical processes (including availability) within required time frames after interruption or failure, which directly matches recovery from a DoS-induced exhaustion event.
- T1499.003responds — A.5.29 explicitly requires plans, compensating controls, and processes to maintain/restore security (including availability) once disruption from an application-exhaustion flood is underway, engaging the core of containment/eradication in response activities, but leaves the bulk of real-time flood handling to other mechanisms.
- T1499.004prevents — A.5.29 requires determining, planning, implementing, testing, and maintaining information security controls (including compensating ones) within business continuity and ICT continuity plans to protect assets and restore security during disruption, which directly constrains the persistent/repeated exploitation path that keeps a DoS condition in place after initial crash/restart.
- T1499.004recovers — A.5.29 explicitly requires plans, controls, and compensating measures to restore the security of information and critical processes following interruption or failure, which directly addresses recovery from the DoS condition and side-effects (data destruction, service stop, etc.) produced by the technique.
- T1499.004responds — A.5.29 explicitly requires plans, compensating controls, and processes to maintain/restore security of critical processes during disruption, which engages several IR-4-style response activities (containment via failover/compensating controls, eradication of the DoS condition, and recovery of security posture) once the exploitation is underway, but leaves the core exploit and initial crash outside its direct containment scope.
- T1528recovers — A.5.29 explicitly requires plans to maintain/restore the security of information (and associated assets such as tokens) following interruption or failure, directly matching the recovers verb after the technique has run.
- T1529detects — A.5.29 requires plans, testing, and processes that maintain/restore security (and detect failures to do so) during disruption events including shutdown/reboot, but does not mandate instrumentation that surfaces the adversary technique itself.
- T1529prevents — A.5.29 requires determining requirements, including security controls and compensating controls in BCM/ICT continuity plans to maintain or restore information security during disruption, which directly counters the availability loss and impeded recovery from T1529 shutdown/reboot (especially post-wipe or inhibit-recovery) for a slice of critical business processes, but does not stop the adversary technique itself from executing.
- T1529recovers — A.5.29 explicitly requires plans, controls, and compensating measures to maintain/restore information security of critical processes following interruption or failure, which directly addresses recovery of security posture after a T1529-induced disruption (including post-BSOD or availability loss).
- T1529responds — A.5.29 explicitly requires plans, controls, compensating measures, and restoration processes that activate once disruption (including shutdown/reboot) is underway to contain effects, maintain security, and recover within time frames, which matches the `responds` verb of containment/eradication during an in-flight event.
- T1531detects — A.5.29 requires plans, testing, and compensating controls that surface when security controls cannot be maintained or when disruption (including account-access removal) occurs, but this is limited to continuity-process monitoring rather than broad or real-time detection of the technique itself.
- T1531prevents — A.5.29 explicitly requires determining requirements, including security controls and compensating controls in BCM/continuity plans to maintain or restore information security (and thus account access) during and after disruption, which constrains the T1531 technique when it is performed as part of a disruption/ransomware event.
- T1531recovers — A.5.29 explicitly requires plans, controls, and compensating measures to maintain or restore the security of information and assets (including account access) following interruption or failure, directly addressing recovery from T1531's availability-impacting account manipulations in disruption scenarios like ransomware.
- T1531responds — A.5.29 explicitly requires plans, compensating controls, and processes to maintain/restore security of critical information and assets once disruption (including account-access-removal impact) is underway, which is the core act named by `responds`.
- T1542recovers — A.5.29 explicitly requires plans, controls, and compensating mechanisms to restore the security of information and critical processes following interruption or failure, which directly matches recovery after a Pre-OS Boot persistence compromise that disrupts normal boot/security state.
- T1542.002recovers — A.5.29 explicitly requires plans to maintain/restore security of critical processes following interruption or failure, and to restore information security to the required level within time frames, which directly matches the recovery verb for a persistence technique that survives re-images.
- T1542.003recovers — A.5.29 explicitly requires plans to maintain/restore security of critical processes following interruption or failure, and to restore information security to the required level within time frames, which directly matches the recovery act after a bootkit has disrupted boot-time integrity.
- T1542.003responds — A.5.29 explicitly requires plans, compensating controls, and processes to maintain/restore information security during and after disruption events (including those from low-level persistence like bootkits), which matches the `responds` act of containment/eradication once the technique is underway.
- T1542.004recovers — A.5.29 explicitly requires plans, controls, and compensating measures to restore the security of information and critical processes (including firmware/boot integrity) to the required level within defined time frames after a disruption or failure, which directly recovers from the post-persistence state left by a ROMMONkit implant.
- T1542.005recovers — A.5.29 explicitly requires plans, controls, and compensating measures to restore the security of information and assets (including network device images and configurations) to the required level within defined time frames following interruption or failure, which directly matches recovery from a TFTP-booted unauthorized image.
- T1543.002prevents — A.5.29 requires determining security requirements, including them in BCM processes, and maintaining/implementing compensating controls during disruption; this can prevent some persistence via systemd services (e.g. by enforcing integrity checks or compensating access controls on unit files during failover/recovery), but leaves most of the technique's core creation/modification vectors during normal operation untouched.
- T1546.007detects — A.5.29 requires plans, testing, and compensating controls that can include monitoring/detection mechanisms within continuity processes, but does not mandate or focus on detecting the specific Netsh Helper DLL persistence technique itself.
- T1547.012detects — A.5.29 requires plans, testing, and compensating controls to maintain/restore information security during disruption, which can include monitoring for anomalies in boot-time services like the print spooler; this surfaces the technique in a disruption context but does not mandate general-purpose detection of the TTP itself.
- T1548.006prevents — A.5.29 requires determining, planning, implementing, testing, and maintaining information security controls (including compensating ones) within business continuity and ICT continuity plans to protect assets during disruption; this can prevent some TCC manipulation vectors that rely on or exploit disrupted states (e.g., SIP disabled, unmaintained controls, or failed continuity of TCC daemon/database protections), but leaves many runtime abuse paths (process injection, inherited permissions from trusted apps) untouched as they are not inherently disruption-dependent.
- T1552.001prevents — A.5.29 requires determining, planning, implementing, testing, and maintaining adapted/compensating information security controls (including within continuity and ICT plans) that can explicitly keep credential-handling protections active or substituted during a disruption, which stops the T1552.001 search technique from succeeding in the disruption window for the slice of cases where the disruption would otherwise expose or weaken those protections.
- T1555.001recovers — A.5.29 explicitly requires plans to maintain/restore the security of information (including credentials) of critical business processes following interruption or failure, and to restore security at the required level and time frames; this matches the recovers verb for the post-exfiltration state after a Keychain credential theft technique has already run.
- T1556.008detects — A.5.29 requires information security controls and monitoring processes to be maintained or adapted within business continuity plans, which can include detection of anomalous activity (such as malicious DLL registration or credential access) during a disruption, but does not mandate or focus on specific detection of this technique.
- T1556.009prevents — A.5.29 requires determining, including in BCM, and maintaining (or compensating for) information security controls during disruption; this directly constrains the T1556.009 technique of disabling/modifying conditional-access policies as part of ensuring persistent access when normal controls cannot be maintained.
- T1557.003detects — A.5.29 requires determining, implementing, and maintaining information security controls (including in continuity plans and as compensating controls) during disruption, which can encompass detection mechanisms for anomalous DHCP behavior or network configuration changes as part of maintaining/restoring security, but this is not a primary or explicit focus of the control.
- T1561prevents — A.5.29 explicitly requires determining, planning, implementing, testing, and maintaining information security controls (including compensating ones) within business continuity and ICT continuity plans to protect or restore information/assets during disruption, which directly constrains the availability-interruption outcome of a disk-wipe technique even though it does not stop the adversary from executing the wipe itself.
- T1561recovers — A.5.29 explicitly requires plans, controls, and compensating measures to maintain/restore security of critical business information and assets following interruption or failure, which directly addresses recovery from the availability loss caused by disk wipe.
- T1561responds — A.5.29 explicitly requires plans, compensating controls, and processes to maintain/restore information security once disruption (including availability interruption from disk wipe) is underway, which is the core act named by `responds`.
- T1561.001detects — A.5.29 requires plans, testing, and compensating controls that can include monitoring/detection mechanisms during disruption events, which would surface disk-wipe activity once underway, but this is only one slice of the control's focus on continuity planning rather than dedicated detection.
- T1561.001prevents — A.5.29 requires determining, planning, implementing, testing and maintaining adapted/compensating information security controls (including within ICT continuity plans) that can explicitly include measures to protect against or limit destructive availability attacks like disk content wipe during a disruption event.
- T1561.001recovers — A.5.29 explicitly requires plans, controls, and compensating measures to maintain or restore the security (including availability) of information and assets following interruption or failure, which directly matches recovery from the availability loss caused by disk content wipe.
- T1561.001responds — A.5.29 explicitly requires plans, compensating controls, and processes to maintain/restore information security (including availability) once disruption from an event like disk-wipe is underway, which matches the `responds` verb of containment/eradication during the incident.
- T1561.002detects — A.5.29 explicitly requires plans, testing, review and evaluation of security during disruption plus processes to maintain/restore controls, which surfaces when disk-structure-wipe techniques cause availability-impacting disruptions, but only as part of broader continuity monitoring rather than direct technique-specific detection.
- T1561.002prevents — A.5.29 requires determining security requirements, including controls and compensating controls in BCM/ICT continuity plans to maintain or restore information security (and thus availability) during disruption, which directly counters the availability-interruption goal of T1561.002 but does not stop the adversary technique itself from executing.
- T1561.002recovers — A.5.29 explicitly requires plans, controls, and compensating measures to maintain or restore the security of information (and availability of critical processes) following interruption or failure, which directly matches recovery after a disk-structure wipe has rendered systems unbootable.
- T1561.002responds — A.5.29 explicitly requires plans, compensating controls, and processes to maintain/restore information security (including availability) once disruption from an attack like T1561.002 is underway, which matches the `responds` verb of containment/eradication during an active event.
- T1565prevents — A.5.29 requires determining, planning, implementing, testing, and maintaining adapted/compensating information security controls (including integrity protections) within BCM and ICT continuity processes so that manipulation during disruption is harder to achieve or sustain; this constrains a slice of T1565 but does not stop the technique outright in normal operations or all disruption scenarios.
- T1565recovers — A.5.29 explicitly requires plans to maintain/restore the security of information (including integrity) of critical business processes following interruption or failure, and to restore it to the required level within required time frames; this directly matches recovery from the post-impact state created by T1565 data manipulation.
- T1565.001prevents — A.5.29 requires determining, planning, implementing, testing, and maintaining information security controls (including compensating ones) during disruption to protect integrity of critical business information, which directly constrains stored data manipulation techniques that target business processes and decision-making during such events, but leaves many non-disruption scenarios and non-critical data untouched.
- T1565.001recovers — A.5.29 explicitly requires plans, controls, and compensating measures to restore the security (including integrity) of information for critical processes following interruption or failure, which directly recovers from the post-impact state created by stored data manipulation.
- T1565.002detects — A.5.29 requires plans, testing, and processes (including monitoring implied by continuity evaluation and restoration) that can surface data manipulation during a declared disruption, but this is scoped only to continuity events rather than general detection of the technique.
- T1565.002prevents — A.5.29 requires determining, planning, implementing, testing, and maintaining adapted/compensating information security controls (including those protecting integrity) within BCM and ICT continuity processes so that critical business processes can continue securely during disruption; this directly constrains the adversary's opportunity to manipulate transmitted data when that manipulation depends on or exploits a disruption-induced gap in controls.
- T1566.004prevents — A.5.29 requires determining, planning, testing, and maintaining (or compensating for) information security controls during disruption, which can include awareness/training and processes that reduce successful social engineering during outages, but does not stop the vishing technique itself from being attempted or succeeding.
- T1567.002detects — A.5.29 requires information security controls, tools, and processes (including monitoring) to be maintained or adapted within continuity plans during disruption, which can surface anomalous exfiltration to cloud storage when it occurs amid a disruption event, but this is scoped only to the disruption context rather than general detection of the technique.
- T1567.004detects — A.5.29 requires plans, testing, and compensating controls that can include monitoring/detection mechanisms during disruption (e.g., to maintain or restore security of critical processes), but this is scoped only to disruption events and does not broadly detect webhook exfiltration in normal operations.
- T1574.008detects — A.5.29 requires information security controls, processes, and compensating controls to be maintained, implemented, and tested within business continuity and ICT continuity plans during disruption, which can include monitoring/detection mechanisms to identify security issues (such as anomalous program execution from hijacked search order) when they arise in a disrupted environment.
- T1574.009prevents — A.5.29 requires determining, including in BCM/ICT continuity plans, and maintaining (or compensating for) information security controls during disruption; this can prevent the technique in planned failover/DR scenarios where unquoted paths would otherwise be introduced or left vulnerable, but leaves the bulk of normal-operation unquoted-path exposures untouched.
- T1578detects — A.5.29 explicitly requires plans, testing, review and evaluation of security during disruption plus processes to maintain controls, which surfaces anomalies or failures in maintaining security (including infrastructure modifications) once disruption or the technique is underway.
- T1578.003detects — A.5.29 requires plans, testing, and compensating controls that can surface anomalous deletions or unrecoverable instances during disruption response, but does not mandate ongoing monitoring or detection mechanisms for the technique itself.
- T1578.003recovers — A.5.29 explicitly requires plans, controls, and compensating measures to restore the security of information (and associated assets) to the required level within required time frames after interruption or failure; this directly recovers from the post-deletion loss of forensic artifacts and evidence that T1578.003 produces.
- T1578.003responds — A.5.29 requires plans, processes and compensating controls that maintain/restore security once disruption (including an adversary-caused deletion of a cloud instance) is underway; this engages the containment/eradication slice of `responds` but leaves the forensic-evidence-removal aspect and non-disruption pre-compromise use cases untouched.
- T1578.004recovers — A.5.29 explicitly requires plans, controls, and compensating measures to maintain or restore the security of information and assets following interruption or failure, which directly addresses recovery from the post-technique state created by snapshot reversion or ephemeral storage reset.
- T1578.005prevents — A.5.29 requires determining requirements, including security controls in BCM/ICT continuity plans, maintaining existing controls or deploying compensating ones during disruption; this constrains an adversary's ability to freely modify cloud compute configs (e.g. quotas, policies, regions) as part of exploiting a disruption, but only for the bounded slice of such modifications that occur during declared disruptions rather than the dominant stealthy/pre-disruption case.
- T1601.001recovers — A.5.29 explicitly requires plans to maintain/restore security of information and critical processes following interruption or failure, and to restore security to the required level within time frames, which directly matches the recovers verb for the post-technique state after a network-device OS patch has altered defenses or introduced capabilities.
- T1601.002recovers — A.5.29 explicitly requires plans, controls, and compensating measures to restore the security of information and critical processes to the required level within defined time frames after interruption or failure, which directly recovers from the weakened state introduced by the downgrade technique.
- T1602.002detects — A.5.29 requires plans, testing, and compensating controls that can include monitoring/detection mechanisms during disruption events, which would surface the technique when it occurs amid a disruption, but the control is scoped only to disruption periods and does not mandate detection outside them or against this specific technique.
- T1611prevents — A.5.29 requires determining, planning, implementing, testing, and maintaining adapted/compensating information security controls (including within continuity/ICT plans) that can explicitly address isolation/separation requirements during disruption, thereby stopping many but not all of the technique's vectors (e.g., misconfigurations, privileged containers, bind mounts) from succeeding.
- T1620detects — A.5.29 requires information security controls and processes (including monitoring) to be maintained or adapted during disruption, which can surface anomalous reflective loading as part of continuity monitoring, but the clause is scoped to disruption events and does not mandate general-purpose detection of the technique itself.
- T1621prevents — A.5.29 requires determining, planning, implementing, testing, and maintaining adapted/compensating information security controls (including MFA-related ones) during disruptions, which can prevent MFA-fatigue or push-bombardment techniques that exploit disrupted or degraded auth states, but leaves many non-disruption scenarios and implementation gaps untouched.
- T1653prevents — A.5.29 requires determining, planning, implementing, testing, and maintaining information security controls (including compensating ones) within business continuity and ICT continuity plans to protect assets and restore security post-disruption, which reaches the slice of T1653 where power-setting abuse is used to survive or extend access across reboots, hibernation, or shutdowns that would otherwise interrupt the adversary.
- T1657prevents — A.5.29 requires determining, planning, implementing, testing, and maintaining adapted/compensating information security controls (including during ICT/business continuity) to protect assets and restore security post-disruption; this constrains the subset of T1657 techniques that rely on or exploit disruption (e.g., ransomware extortion after T1486, or using financial theft as cover for T1485/business disruption), but leaves the majority of social-engineering, BEC, impersonation, and direct technical theft vectors untouched.
- T1657recovers — A.5.29 explicitly requires plans, controls, and compensating measures to maintain or restore the security of information and assets (including monetary resources) following interruption or failure, directly addressing recovery from the availability loss and business disruption caused by financial theft techniques such as ransomware extortion.
- T1657responds — A.5.29 requires plans, controls, and compensating measures to maintain/restore security (including during/after disruption from ransomware extortion or BEC that realises financial theft), which engages the containment/eradication/follow-up activities of `responds` once the technique is underway; partial because the clause is scoped to business continuity for critical processes rather than full incident response against all financial-theft vectors (e.g., pre-impact social engineering or cryptocurrency exploits).
- T1667prevents — A.5.29 requires determining, planning, implementing, testing, and maintaining adapted/compensating information security controls (including within business continuity and ICT continuity plans) to protect information and assets during disruption, which directly counters the inbox overload, buried alerts, and operational disruption caused by T1667.
- T1667recovers — A.5.29 explicitly requires plans, controls, and compensating measures to restore the security of information and critical processes following interruption or failure, which directly matches recovering from the inbox-flood disruption and buried legitimate messages (including security alerts) caused by T1667.
- T1667responds — A.5.29 requires plans, controls, and compensating measures to maintain/restore information security once a disruption (such as inbox flooding) is underway, which matches the `responds` verb; extent is only partial because the clause is scoped to security controls during business/ICT continuity rather than the full set of incident-response actions (containment, eradication, actor removal) that the verb prototypically names in the event-lane anchors.
- T1677prevents — A.5.29 requires determining security requirements, including them in BCM processes, and maintaining/implementing compensating controls during disruption; this can prevent some poisoning vectors (e.g. via maintained controls or compensating measures in continuity plans for critical build processes) but leaves many others (e.g. public PR-based or indirect injection in non-disruption scenarios) untouched.
- T1684prevents — A.5.29 requires determining, planning, implementing, testing, and maintaining information security controls (including compensating ones) within business continuity processes to protect assets during disruption; this constrains some social engineering vectors that exploit disrupted states or urgency/scare tactics tied to interruptions, but leaves the bulk of routine trust-building, phishing, and emotional manipulation techniques untouched.
- T1685prevents — A.5.29 requires determining requirements, including security controls and compensating controls in BCM/ICT continuity plans to maintain or restore information security during disruption, which constrains some T1685 vectors (e.g., by planning to sustain or failover logging/EDR/sensor mechanisms) but does not stop the technique from running against unaddressed or non-critical tools.
- T1685recovers — A.5.29 explicitly requires plans, controls, and compensating measures to restore the security of information and critical processes (including security tools and visibility mechanisms) to the required level within defined time frames after a disruption, which directly matches recovery from an adversary technique that has already impaired those tools.
- T1685responds — A.5.29 explicitly requires plans, compensating controls, and processes to maintain/restore security (including of tools and logging) once disruption occurs, which directly matches the `responds` act of containing and eradicating an in-flight technique that has already begun.
- T1685.002prevents — A.5.29 requires determining, planning, implementing, testing, and maintaining information security controls (including compensating ones) within business continuity and ICT continuity processes to protect information during disruption; this directly constrains an adversary's ability to disable/modify cloud logging as a disruption technique in many scenarios, but leaves residual cases where the technique can still succeed before or despite the continuity measures.
- T1685.005detects — A.5.29 requires plans, testing, and compensating controls that can include monitoring/detection mechanisms active during disruption, which would surface the clearing technique when it occurs in that context; this is only a slice of the technique's possible executions, not the dominant case.
- T1685.005recovers — A.5.29 explicitly requires plans, controls, and compensating measures to maintain/restore information security (including logging integrity) of critical processes after interruption or failure, which recovers the audit trail destroyed by T1685.005; mostly because the control is scoped to critical-business-process information rather than every possible Windows event log.
- T1686detects — A.5.29 requires plans, testing, and compensating controls that can include monitoring/detection mechanisms during disruption, which would surface firewall tampering as an anomalous event, but this is only a minority slice of the control's overall focus on continuity planning and restoration rather than dedicated detection.
- T1686prevents — A.5.29 requires determining, planning, implementing, testing, and maintaining information security controls (including compensating ones) within business continuity and ICT continuity plans to protect assets during disruption; this reaches a slice of T1686 where the firewall-tampering technique is attempted during a declared disruption, but leaves the dominant pre-disruption or non-disruption execution paths untouched.
- T1686.001detects — A.5.29 requires plans, testing, and compensating controls that can include monitoring/detection mechanisms during disruption, which would surface adversarial firewall changes as an anomalous security event, but this is only one narrow slice of the control's overall continuity focus and does not address the technique in normal operations.
- T1686.003detects — A.5.29 requires plans, testing, and compensating controls that can include monitoring/detection mechanisms during disruption, but does not mandate or focus on detecting the specific firewall modification technique itself.
- T1687recovers — A.5.29 explicitly requires plans to maintain/restore security of information and implement compensating controls during disruption, which recovers defensive posture after impairment from T1687 exploitation of security components.
- T1688prevents — A.5.29 requires determining, planning, implementing, testing and maintaining information security controls (including compensating ones) that explicitly continue to protect assets during a disruption; this directly constrains the T1688 technique of forcing a limited-boot state that evades endpoint defenses, but only for the subset of defenses covered by the organization's continuity plans rather than all possible endpoint security.
- T1689prevents — A.5.29 requires determining, planning, implementing, testing, and maintaining adapted/compensating information security controls (including during ICT continuity) that can block or constrain the use of vulnerable downgraded modes, versions, or features that bypass updated defenses, but this is a general continuity-planning requirement that does not specifically target or guarantee prevention of downgrade techniques.
Prevented OWASP Web Top 10 (2025) risks (9)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A01mitigates — A.5.29 requires maintaining/restoring security (including access controls) and deploying compensating controls during disruption, which bounds the blast radius or duration of realized broken-access-control weaknesses when continuity is invoked, but does not address the authorization failures themselves.
- A02mitigates — A.5.29 requires maintaining or adapting security controls (including compensating ones) during disruption, which can bound the realized impact or exposure window of a misconfiguration that becomes active only under failure conditions, but does not address the underlying weak defaults or incomplete hardening that define the weakness.
- A05mitigates — A.5.29 requires maintaining or restoring security controls (including compensating ones) during disruption, which can bound the realized impact of an injection that succeeds during the outage window, but does not address the neutralization failure itself.
- A08mitigates — A.5.29 requires maintaining/restoring security (incl. integrity) and compensating controls during disruption, which bounds the realized impact of an integrity failure (e.g. via continuity plans or workarounds) but does not address the core weakness of trusting unverified code/data.
- A09mitigates — A.5.29 requires maintaining or adapting security controls (including logging/alerting) during disruption via plans, processes and compensating controls, which bounds the realized impact of missing or non-functional logging by ensuring some visibility or failover persists; it does not address the core absence or design defects that cause the failures in normal operation.
- A10mitigates — A.5.29 requires maintaining/restoring security (including via compensating controls) during disruption, which bounds the impact of mishandled exceptions that surface during outages or error states, but does not address the root causes of information leaks, fail-open behavior, or inconsistent states in exception paths.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.