Description
The information system prevents unauthorized and unintended information transfer via shared system resources.
Supplemental Guidance
Control of information system remnance, sometimes referred to as object reuse, or data remnance, prevents information, including encrypted representations of information, produced by the actions of a prior user/role (or the actions of a process acting on behalf of a prior user/role) from being available to any current user/role (or current process) that obtains access to a shared system resource (e.g., registers, main memory, secondary storage) after that resource has been released back to the information system.
Enhancements
(0) None.
MITRE ATT&CK Techniques (29)
ATT&CK v16.1Techniques mitigated by this control, mapped via CTID.
Reconnaissance 1 Defense Evasion 5 Credential Access 12 Discovery 1 Lateral Movement 1 Collection 7 Exfiltration 1 Impact 4
Reconnaissance
Defense Evasion
Credential Access
T1040 Network Sniffing T1552 Unsecured Credentials T1557 Adversary-in-the-Middle T1558 Steal or Forge Kerberos Tickets T1552.001 Credentials In Files T1552.002 Credentials in Registry T1552.004 Private Keys T1557.002 ARP Cache Poisoning T1558.002 Silver Ticket T1558.003 Kerberoasting T1558.004 AS-REP Roasting T1558.005 Ccache Files
Discovery
Lateral Movement
Collection
Exfiltration
Compliance Mappings
NIST CSF 2.0
PR.DS-10
ANSSI
Hygiene.19SecNumCloud.9.3
FINMA Circular 2023/1
IV.D(78)IV.E(83)
OSFI B-13
B-13.3.2
EU GDPR
Art.32(1)(a)Art.5(1)(f)
EU DORA
Art.9(4)(b)
RBI CSF
Annex1.4
FISC Security Guidelines
FISC.T5
MLPS 2.0
8.1.4.108.2
UAE IA
T7
Qatar NIA
AMCS
BoG CISD
CISD-VI
IOSCO Cyber Resilience
PROT-3
BCBS 239
Principle 2
CPMI-IOSCO PFMI
CG.PR
FFIEC IS
II.C.18
HIPAA Security Rule
§164.308(a)(4)(i)
ECB CROE
CROE.2.3.5
BOT Cyber Resilience
Ch2.4
CMMC 2.0
SC
Common Criteria
CC Part 2 — FDPCC Part 2 — FPT
FDA Cybersecurity Guidance
SA-4
OWASP MASVS v2.1
MASVS-STORAGE-2MASVS-PLATFORM-3
Basel SCO60
SCO60.64
SEC Custody (Digital Assets)
SEC-CD-04
ISO 17799 (legacy)
10.8.1
COBIT 4.1 (legacy)
None.