Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family SC

SC-41Port and I/O Device Access

{{ insert: param, sc-41_odp.02 }} disable or remove {{ insert: param, sc-41_odp.01 }} on the following systems or system components: {{ insert: param, sc-41_odp.03 }}.

Last updated: 09 May 2026 03:25 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (5)

Weaknesses this control addresses (8)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-284Improper Access Control4,832Disabling or removing ports and I/O devices directly enforces hardware-level access control by eliminating entry points.
CWE-923Improper Restriction of Communication Channel to Intended Endpoints57Restricts communication channels to only intended endpoints by eliminating unnecessary ports and devices.
CWE-300Channel Accessible by Non-Endpoint53Eliminates channels that could be accessed by non-endpoint actors through disabled ports and devices.
CWE-420Unprotected Alternate Channel37Removes or disables unprotected alternate I/O channels that could otherwise be used to bypass primary controls.
CWE-1191On-Chip Debug and Test Interface With Improper Access Control20Directly mitigates exposure of on-chip debug and test interfaces by disabling or removing them.
CWE-1263Improper Physical Access Control13Reduces physical access attack surface by disabling physical ports and I/O devices.
CWE-1244Internal Asset Exposed to Unsafe Debug Access Level or State11Prevents internal assets from being exposed through debug or test access levels by removing those interfaces.
CWE-1299Missing Protection Mechanism for Alternate Hardware Interface11Provides protection for alternate hardware interfaces by disabling them when not required.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2026-307041.89.10.0006good
CVE-2024-481231.78.40.0006good
CVE-2026-290931.68.10.0004good
CVE-2024-554071.67.80.0007good
CVE-2024-554121.67.80.0002good
CVE-2026-250861.57.70.0002good
CVE-2025-301132.09.80.0011good
CVE-2025-543042.09.80.0008good
CVE-2026-258071.88.80.0014good
CVE-2026-271821.78.40.0013good
CVE-2025-552211.78.60.0007good
CVE-2024-554131.67.80.0002good
CVE-2025-301411.57.50.0025good
CVE-2025-594032.19.80.0275good
CVE-2026-20382.09.80.0036good
CVE-2026-263332.09.80.0020good
CVE-2025-301372.09.80.0025good
CVE-2026-62642.09.80.0010good
CVE-2025-666022.09.80.0006good
CVE-2022-509252.09.80.0003good
CVE-2025-342021.88.80.0050good
CVE-2024-455611.67.80.0011partial
CVE-2026-234471.67.80.0001partial
CVE-2026-221631.67.80.0001partial
CVE-2022-492911.67.80.0002partial

Other controls in family SC

SC-1 SC-10 SC-11 SC-12 SC-13 SC-14 SC-15 SC-16 SC-17 SC-18 SC-19 SC-2 SC-20 SC-21 SC-22 SC-23 SC-24 SC-25 SC-26 SC-27 SC-28 SC-29 SC-3 SC-30 SC-31 SC-32 SC-33 SC-34 SC-35 SC-36 SC-37 SC-38 SC-39 SC-4 SC-40 SC-42 SC-43 SC-44 SC-45 SC-46 SC-47 SC-48 SC-49 SC-5 SC-50 SC-51 SC-6 SC-7 SC-8 SC-9