Under active development Content is continuously updated and improved

SC-30(4)Concealment And Misdirection

Technical

>Control Description

CONCEALMENT AND MISDIRECTION | MISLEADING INFORMATION The organization employs realistic, but misleading information in organization-defined information system components with regard to its security state or posture.

>Supplemental Guidance

This control enhancement misleads potential adversaries regarding the nature and extent of security safeguards deployed by organizations. As a result, adversaries may employ incorrect (and as a result ineffective) attack techniques. One way of misleading adversaries is for organizations to place misleading information regarding the specific security controls deployed in external information systems that are known to be accessed or targeted by adversaries.

Another technique is the use of deception nets (e.g., honeynets, virtualized environments) that mimic actual aspects of organizational information systems but use, for example, out-of-date software configurations.

Ask AI

Configure your API key to use AI features.