Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family SI

SI-5Security Alerts, Advisories, and Directives

Receive system security alerts, advisories, and directives from {{ insert: param, si-05_odp.01 }} on an ongoing basis; Generate internal security alerts, advisories, and directives as deemed necessary; Disseminate security alerts, advisories, and directives to: {{ insert: param, si-05_odp.02 }} ; and Implement security directives in accordance with established time frames, or notify the issuing organization of the degree of noncompliance.

Last updated: 09 May 2026 03:25 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (4)

Weaknesses this control addresses (4)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-798Use of Hard-coded Credentials1,955Advisories about products containing hard-coded credentials allow organizations to apply mitigations or avoid affected components before exploitation.
CWE-327Use of a Broken or Risky Cryptographic Algorithm736Security alerts and directives routinely identify broken or risky cryptographic algorithms and require their replacement within defined time frames.
CWE-693Protection Mechanism Failure476Implementing issued security directives maintains the effectiveness of existing protection mechanisms against newly discovered bypasses or failures.
CWE-1104Use of Unmaintained Third Party Components19Ongoing receipt and implementation of security advisories directly enables timely replacement or mitigation of unmaintained third-party components before known vulnerabilities are exploited.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2024-55591 KEV9.69.80.9406good
CVE-2025-64446 KEV9.59.80.9291good
CVE-2026-21513 KEV5.48.80.2811good
CVE-2025-59718 KEV4.59.80.0939good
CVE-2026-34621 KEV4.38.60.0990partial
CVE-2026-21525 KEV3.86.20.0939partial
CVE-2025-24990 KEV3.77.80.0276good
CVE-2026-32202 KEV3.34.30.0719partial
CVE-2025-597072.09.80.0031good
CVE-2025-593882.09.80.0019good
CVE-2026-27612.010.00.0014good
CVE-2025-592452.09.80.0109good
CVE-2026-46922.010.00.0003good
CVE-2026-67682.09.80.0005good
CVE-2026-314362.09.80.0006partial
CVE-2026-67712.09.80.0006partial
CVE-2026-27642.09.80.0003partial
CVE-2026-27842.09.80.0002partial
CVE-2026-08792.09.80.0003partial
CVE-2025-80312.09.80.0015partial
CVE-2026-314481.99.40.0007good
CVE-2025-329911.89.00.0029good
CVE-2025-136591.88.80.0061partial
CVE-2026-47241.89.10.0002good
CVE-2025-19141.88.80.0095good

Other controls in family SI

SI-1 SI-10 SI-11 SI-12 SI-13 SI-14 SI-15 SI-16 SI-17 SI-18 SI-19 SI-2 SI-20 SI-21 SI-22 SI-23 SI-3 SI-4 SI-6 SI-7 SI-8 SI-9