Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family SC

SC-16Transmission of Security and Privacy Attributes

Associate {{ insert: param, sc-16_prm_1 }} with information exchanged between systems and between system components.

Last updated: 09 May 2026 03:25 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (5)

Weaknesses this control addresses (5)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-200Exposure of Sensitive Information to an Unauthorized Actor10,204Associating security/privacy attributes with exchanged data enables receiving systems to enforce handling rules and avoid unauthorized disclosure.
CWE-284Improper Access Control4,832Transmitting bound security attributes preserves access-control context across system boundaries, directly reducing improper access control.
CWE-285Improper Authorization1,230Security attributes carried with data allow consistent authorization decisions between components and external systems.
CWE-807Reliance on Untrusted Inputs in a Security Decision74Providing authoritative attributes with the data reduces the need for security decisions to rely on untrusted external inputs.
CWE-501Trust Boundary Violation24Explicitly binding attributes to information crossing trust boundaries prevents loss of security context that leads to trust-boundary violations.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2026-320141.68.00.0003good

Other controls in family SC

SC-1 SC-10 SC-11 SC-12 SC-13 SC-14 SC-15 SC-17 SC-18 SC-19 SC-2 SC-20 SC-21 SC-22 SC-23 SC-24 SC-25 SC-26 SC-27 SC-28 SC-29 SC-3 SC-30 SC-31 SC-32 SC-33 SC-34 SC-35 SC-36 SC-37 SC-38 SC-39 SC-4 SC-40 SC-41 SC-42 SC-43 SC-44 SC-45 SC-46 SC-47 SC-48 SC-49 SC-5 SC-50 SC-51 SC-6 SC-7 SC-8 SC-9