NIST 800-53 Supply Chain Risk Management Capability Group

All Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name
SR-11 Component Authenticity mitigates T1195 Supply Chain Compromise
SR-11 Component Authenticity mitigates T1195.001 Compromise Software Dependencies and Development Tools
SR-11 Component Authenticity mitigates T1195.002 Compromise Software Supply Chain
SR-11 Component Authenticity mitigates T1195.003 Compromise Hardware Supply Chain
SR-11 Component Authenticity mitigates T1554 Compromise Host Software Binary
SR-04 Provenance mitigates T1195 Supply Chain Compromise
SR-04 Provenance mitigates T1195.001 Compromise Software Dependencies and Development Tools
SR-04 Provenance mitigates T1195.002 Compromise Software Supply Chain
SR-04 Provenance mitigates T1195.003 Compromise Hardware Supply Chain
SR-04 Provenance mitigates T1554 Compromise Host Software Binary
SR-05 Acquisition Strategies, Tools, and Methods mitigates T1195 Supply Chain Compromise
SR-05 Acquisition Strategies, Tools, and Methods mitigates T1195.001 Compromise Software Dependencies and Development Tools
SR-05 Acquisition Strategies, Tools, and Methods mitigates T1195.002 Compromise Software Supply Chain
SR-05 Acquisition Strategies, Tools, and Methods mitigates T1195.003 Compromise Hardware Supply Chain
SR-05 Acquisition Strategies, Tools, and Methods mitigates T1554 Compromise Host Software Binary
SR-04 Provenance mitigates T1041 Exfiltration Over C2 Channel
SR-11 Component Authenticity mitigates T1059.002 AppleScript
SR-05 Acquisition Strategies, Tools, and Methods mitigates T1059.002 AppleScript
SR-11 Component Authenticity mitigates T1204.003 Malicious Image
SR-11 Component Authenticity mitigates T1505 Server Software Component
SR-11 Component Authenticity mitigates T1505.001 SQL Stored Procedures
SR-11 Component Authenticity mitigates T1505.002 Transport Agent
SR-11 Component Authenticity mitigates T1505.004 IIS Components
SR-11 Component Authenticity mitigates T1546.006 LC_LOAD_DYLIB Addition
SR-11 Component Authenticity mitigates T1601 Modify System Image
SR-11 Component Authenticity mitigates T1601.001 Patch System Image
SR-11 Component Authenticity mitigates T1601.002 Downgrade System Image
SR-04 Provenance mitigates T1048 Exfiltration Over Alternative Protocol
SR-04 Provenance mitigates T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
SR-04 Provenance mitigates T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
SR-04 Provenance mitigates T1052 Exfiltration Over Physical Medium
SR-04 Provenance mitigates T1052.001 Exfiltration over USB
SR-04 Provenance mitigates T1059.002 AppleScript
SR-04 Provenance mitigates T1204.003 Malicious Image
SR-04 Provenance mitigates T1505 Server Software Component
SR-04 Provenance mitigates T1505.001 SQL Stored Procedures
SR-04 Provenance mitigates T1505.002 Transport Agent
SR-04 Provenance mitigates T1505.004 IIS Components
SR-04 Provenance mitigates T1546.006 LC_LOAD_DYLIB Addition
SR-04 Provenance mitigates T1567 Exfiltration Over Web Service
SR-04 Provenance mitigates T1601 Modify System Image
SR-04 Provenance mitigates T1601.001 Patch System Image
SR-04 Provenance mitigates T1601.002 Downgrade System Image
SR-05 Acquisition Strategies, Tools, and Methods mitigates T1204.003 Malicious Image
SR-05 Acquisition Strategies, Tools, and Methods mitigates T1505 Server Software Component
SR-05 Acquisition Strategies, Tools, and Methods mitigates T1505.001 SQL Stored Procedures
SR-05 Acquisition Strategies, Tools, and Methods mitigates T1505.002 Transport Agent
SR-05 Acquisition Strategies, Tools, and Methods mitigates T1505.004 IIS Components
SR-05 Acquisition Strategies, Tools, and Methods mitigates T1546.006 LC_LOAD_DYLIB Addition
SR-05 Acquisition Strategies, Tools, and Methods mitigates T1601 Modify System Image
SR-05 Acquisition Strategies, Tools, and Methods mitigates T1601.001 Patch System Image
SR-05 Acquisition Strategies, Tools, and Methods mitigates T1601.002 Downgrade System Image

Capabilities

Capability ID Capability Name Number of Mappings
SR-11 Component Authenticity 15
SR-04 Provenance 22
SR-05 Acquisition Strategies, Tools, and Methods 15