Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family PM

PM-32Purposing

Analyze {{ insert: param, pm-32_odp }} supporting mission essential services or functions to ensure that the information resources are being used consistent with their intended purpose.

Last updated: 09 May 2026 03:25 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (0)

Weaknesses this control addresses (6)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-284Improper Access Control4,832Periodic purpose analysis directly detects and corrects access control decisions that permit use outside the defined mission function.
CWE-269Improper Privilege Management2,907Drives ongoing review and correction of privilege assignments that have drifted from intended operational need.
CWE-732Incorrect Permission Assignment for Critical Resource1,824Triggers re-evaluation of permission assignments on critical resources when usage deviates from declared purpose.
CWE-285Improper Authorization1,230Enforces that authorization rules remain consistent with the documented intended purpose of each resource.
CWE-250Execution with Unnecessary Privileges305Identifies privileges or capabilities that exceed what is required for the stated mission purpose, enabling removal.
CWE-653Improper Isolation or Compartmentalization52Verifies that mission-essential functions remain isolated and not repurposed across compartment boundaries.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
No CVEs annotated to this control yet — the per-CVE backfill is in progress.

Other controls in family PM

PM-1 PM-10 PM-11 PM-12 PM-13 PM-14 PM-15 PM-16 PM-17 PM-18 PM-19 PM-2 PM-20 PM-21 PM-22 PM-23 PM-24 PM-25 PM-26 PM-27 PM-28 PM-29 PM-3 PM-30 PM-31 PM-4 PM-5 PM-6 PM-7 PM-8 PM-9