Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family SC

SC-22Architecture and Provisioning for Name/Address Resolution Service

Ensure the systems that collectively provide name/address resolution service for an organization are fault-tolerant and implement internal and external role separation.

Last updated: 09 May 2026 03:25 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (7)

Weaknesses this control addresses (6)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-200Exposure of Sensitive Information to an Unauthorized Actor10,204Internal/external role separation directly prevents external actors from obtaining sensitive internal host and network information via name resolution.
CWE-284Improper Access Control4,832Role separation implements access control boundaries between internal and external name resolution services.
CWE-400Uncontrolled Resource Consumption3,324Fault tolerance reduces the impact of resource-exhaustion attacks against the organization's name services.
CWE-770Allocation of Resources Without Limits or Throttling1,979Redundant provisioning limits the effectiveness of uncontrolled allocation attacks on resolution infrastructure.
CWE-668Exposure of Resource to Wrong Sphere779Fault-tolerant architecture with role separation keeps internal resolution resources from being exposed to external spheres.
CWE-923Improper Restriction of Communication Channel to Intended Endpoints57Explicit internal/external separation restricts name-resolution channels to their intended communication endpoints.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2025-301401.57.50.0021good
CVE-2025-710581.89.10.0014partial
CVE-2025-301321.89.10.0008good
CVE-2024-571741.68.10.0026good

Other controls in family SC

SC-1 SC-10 SC-11 SC-12 SC-13 SC-14 SC-15 SC-16 SC-17 SC-18 SC-19 SC-2 SC-20 SC-21 SC-23 SC-24 SC-25 SC-26 SC-27 SC-28 SC-29 SC-3 SC-30 SC-31 SC-32 SC-33 SC-34 SC-35 SC-36 SC-37 SC-38 SC-39 SC-4 SC-40 SC-41 SC-42 SC-43 SC-44 SC-45 SC-46 SC-47 SC-48 SC-49 SC-5 SC-50 SC-51 SC-6 SC-7 SC-8 SC-9