Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family SI

SI-15Information Output Filtering

Validate information output from the following software programs and/or applications to ensure that the information is consistent with the expected content: {{ insert: param, si-15_odp }}.

Last updated: 09 May 2026 03:25 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (42)

Weaknesses this control addresses (6)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')50,384Output validation against expected content can reject or sanitize script content in generated web pages, reducing XSS exploitability.
CWE-200Exposure of Sensitive Information to an Unauthorized Actor10,204Filtering output to only permitted content stops unintended disclosure of sensitive information to unauthorized actors.
CWE-532Insertion of Sensitive Information into Log File1,378Checking application output against expected content catches insertion of sensitive values into log streams or files.
CWE-209Generation of Error Message Containing Sensitive Information642Validation ensures error messages contain only expected, non-sensitive content and blocks leakage via verbose errors.
CWE-116Improper Encoding or Escaping of Output450Validating that output matches expected content directly mitigates failures to properly encode or escape data for its destination context.
CWE-117Improper Output Neutralization for Logs95Requiring output to conform to expected content prevents unneutralized data from reaching logs.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2025-27915 KEV4.65.40.2605good
CVE-2025-441362.79.80.1302good
CVE-2025-244592.34.60.2230good
CVE-2025-507382.39.80.0538good
CVE-2025-03142.28.70.0790good
CVE-2024-104412.19.80.0189good
CVE-2024-576862.09.80.0098good
CVE-2026-404702.09.90.0005good
CVE-2026-404722.09.90.0005good
CVE-2025-143202.09.80.0005good
CVE-2026-259962.09.80.0008good
CVE-2026-227921.99.60.0044good
CVE-2025-302231.99.30.0034good
CVE-2026-291831.99.30.0040good
CVE-2026-349321.99.30.0001good
CVE-2026-331361.99.30.0005good
CVE-2025-660241.99.00.0086good
CVE-2026-327541.99.30.0008good
CVE-2026-318451.99.30.0002good
CVE-2025-664811.99.60.0021good
CVE-2024-562891.97.10.0755good
CVE-2026-329401.99.30.0009good
CVE-2025-03761.98.70.0237good
CVE-2026-309281.97.50.0641good
CVE-2026-420901.99.60.0016good

Other controls in family SI

SI-1 SI-10 SI-11 SI-12 SI-13 SI-14 SI-16 SI-17 SI-18 SI-19 SI-2 SI-20 SI-21 SI-22 SI-23 SI-3 SI-4 SI-5 SI-6 SI-7 SI-8 SI-9