{"data":{"id":"SC-04","name":"Information in Shared System Resources","family":"SC","family_name":"System and Communications Protection","withdrawn":false,"description":"Prevent unauthorized and unintended information transfer via shared system resources.","supplemental_guidance":"Preventing unauthorized and unintended information transfer via shared system resources stops information produced by the actions of prior users or roles (or the actions of processes acting on behalf of prior users or roles) from being available to current users or roles (or current processes acting on behalf of current users or roles) that obtain access to shared system resources after those resources have been released back to the system. Information in shared system resources also applies to encrypted representations of information. In other contexts, control of information in shared system resources is referred to as object reuse and residual information protection. Information in shared system resources does not address information remanence, which refers to the residual representation of data that has been nominally deleted; covert channels (including storage and timing channels), where shared system resources are manipulated to violate information flow restrictions; or components within systems for which there are only single users or roles.","enhancements":[{"id":"SC-04(01)","name":"Security Levels","withdrawn":true,"incorporated_into":["SC-04"]},{"id":"SC-04(02)","name":"Multilevel or Periods Processing","statement":"Prevent unauthorized information transfer via shared resources in accordance with [Assignment: organization-defined procedures] when system processing explicitly switches between different information classification levels or security categories.","baselines":[]}],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"SC-04","name":"Information in Shared System Resources","description":"Prevent unauthorized and unintended information transfer via shared system resources.","discussion":"Preventing unauthorized and unintended information transfer via shared system resources stops information produced by the actions of prior users or roles (or the actions of processes acting on behalf of prior users or roles) from being available to current users or roles (or current processes acting on behalf of current users or roles) that obtain access to shared system resources after those resources have been released back to the system. Information in shared system resources also applies to encrypted representations of information. In other contexts, control of information in shared system resources is referred to as object reuse and residual information protection. Information in shared system resources does not address information remanence, which refers to the residual representation of data that has been nominally deleted; covert channels (including storage and timing channels), where shared system resources are manipulated to violate information flow restrictions; or components within systems for which there are only single users or roles.","related_controls":["AC-03","AC-04","SA-08"],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":""}},"compliance_mappings":{"iso_27001_2022":[],"iso_27002_2022":[],"cobit_2019":[],"pci_dss_v4":[],"nist_csf_2":["PR.DS-01","PR.DS-02","PR.DS-10","PR.IR-01"],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":["Hygiene.19","SecNumCloud.9.3"],"osfi_b13":["B-13.3.2"],"finma_circular":["IV.D(78)","IV.E(83)"],"gdpr":["Art.5(1)(f)","Art.32(1)(a)"],"dora":["Art.9(4)(b)"],"bio2":[],"rbi_csf":["Annex1.4"],"fisc":["FISC.T5"],"lgpd_bcb":[],"hkma_tme1":[],"mlps_2":["8.1.4.10","8.2"],"dnb_good_practice":[],"cra":[],"swift_cscf":[],"qatar_nia":["AM","CS"],"uae_ia":["T7"],"bog_cisd":["CISD-VI"],"bcbs_239":["Principle 2"],"bot_cyber":["Ch2.4"],"cpmi_pfmi":["CG.PR"],"ecb_croe":["CROE.2.3.5"],"ffiec_is":["II.C.18"],"hipaa_sr":["§164.308(a)(4)(i)"],"iosco_cyber":["PROT-3"],"cmmc_2":["SC"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":["CC Part 2 — FDP","CC Part 2 — FPT"],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":["SA-4"],"hitrust_csf":[],"iso_27799":[],"lloyds_ms":[],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":["MASVS-PLATFORM-3","MASVS-STORAGE-2"],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":["SCO60.64"],"bssc":[],"sec_custody_digital":["SEC-CD-04"],"dpdpa":[]},"attack_techniques":[{"id":"T1040","name":"Network Sniffing","tactics":["credential-access","discovery"],"mapping_type":"mitigates","mapping_rationale":"Preventing unauthorized information transfer via shared system resources eliminates residual network data in shared buffers that adversaries could access through network sniffing of memory-resident packet data."},{"id":"T1070","name":"Indicator Removal","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Information remnance controls that securely clear shared system resources prevent adversaries from recovering previously deleted log data, audit records, or forensic evidence from residual shared storage."},{"id":"T1080","name":"Taint Shared Content","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Preventing information leakage through shared resources limits adversaries' ability to taint shared content by ensuring residual data from one user session cannot be accessed or modified by subsequent users."},{"id":"T1119","name":"Automated Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Information remnance controls that clear shared memory and temporary storage after use prevent automated collection tools from harvesting residual sensitive data from previously released shared system resources."},{"id":"T1530","name":"Data from Cloud Storage","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Preventing unauthorized information transfer through shared cloud storage resources ensures that residual data from cloud object operations cannot be recovered by unauthorized users accessing the same shared infrastructure."},{"id":"T1552","name":"Unsecured Credentials","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Information remnance controls that securely erase credentials from shared memory, temporary files, and swap space after use prevent adversaries from recovering residual credential data from released system resources."},{"id":"T1557","name":"Adversary-in-the-Middle","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Preventing information leakage through shared network resources reduces the data available to adversaries positioned as intermediaries, as residual authentication material is cleared from shared communication buffers."},{"id":"T1558","name":"Steal or Forge Kerberos Tickets","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Information remnance controls that clear Kerberos ticket data from shared memory after session termination prevent adversaries from recovering residual ticket material for Kerberos-based credential attacks."},{"id":"T1565","name":"Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Preventing unauthorized information transfer via shared resources maintains data integrity by ensuring residual data from previous operations cannot be accessed or manipulated by subsequent unauthorized processes."},{"id":"T1602","name":"Data from Configuration Repository","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Information remnance controls that securely clear configuration data from shared resources prevent adversaries from recovering residual device configuration information from previously used shared management interfaces."},{"id":"T1020.001","name":"Traffic Duplication","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Controlling information remnance in shared network resources prevents residual traffic data from being available through duplicated network paths, reducing exposure from inadvertent traffic data persistence."},{"id":"T1070.001","name":"Clear Windows Event Logs","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Information remnance controls on shared storage resources ensure that cleared Windows event log data is properly overwritten, preventing adversary recovery of residual log entries from shared disk storage."},{"id":"T1070.002","name":"Clear Linux or Mac System Logs","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Preventing information transfer through shared resources ensures that Linux/Mac system log data properly cleared from shared storage cannot be recovered from residual data in released storage blocks."},{"id":"T1070.008","name":"Clear Mailbox Data","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Information remnance controls that securely clear mailbox data from shared storage prevent adversaries from recovering cleared email content from residual data in shared messaging infrastructure."},{"id":"T1552.001","name":"Credentials In Files","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Information remnance controls that securely clear credential data from shared temporary files and memory prevent adversaries from recovering passwords and tokens from residual file system data."},{"id":"T1552.002","name":"Credentials in Registry","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Preventing information persistence in shared registry resources ensures credentials stored in registry values are securely cleared when no longer needed, preventing recovery from residual registry data."},{"id":"T1552.004","name":"Private Keys","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Information remnance controls that securely clear private key material from shared memory and temporary storage after cryptographic operations prevent adversaries from recovering residual key data."},{"id":"T1557.002","name":"ARP Cache Poisoning","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Preventing information leakage through shared network resources—including ARP caches and routing tables—limits the residual network state information available for ARP cache poisoning reconnaissance."},{"id":"T1558.002","name":"Silver Ticket","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Information remnance controls that clear Kerberos service ticket material from shared memory prevent adversaries from recovering residual ticket data usable for silver ticket forgery from released resources."},{"id":"T1558.003","name":"Kerberoasting","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Preventing credential remnance in shared authentication resources limits the Kerberos service ticket material available in shared memory that adversaries could extract for offline Kerberoasting attacks."},{"id":"T1558.004","name":"AS-REP Roasting","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Information remnance controls that clear AS-REP response data from shared authentication buffers prevent adversaries from recovering residual Kerberos authentication material for AS-REP roasting attacks."},{"id":"T1558.005","name":"Ccache Files","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Preventing information persistence in shared credential caches ensures Kerberos ccache file contents are securely cleared from shared storage, eliminating residual ticket data available for theft."},{"id":"T1564.009","name":"Resource Forking","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Information remnance controls that securely clear alternate data streams and resource fork data from shared storage prevent adversaries from hiding persistent payloads in residual fork data."},{"id":"T1565.001","name":"Stored Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Information remnance controls that enforce data clearing on shared storage resources prevent adversaries from accessing or manipulating residual stored data that persists after legitimate data operations."},{"id":"T1565.002","name":"Transmitted Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Preventing information leakage through shared communication buffers ensures residual transmitted data cannot be accessed or modified by subsequent processes, maintaining transmission integrity."},{"id":"T1565.003","name":"Runtime Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Information remnance controls that clear runtime data from shared memory regions after process completion prevent adversaries from accessing residual computation data for runtime manipulation attacks."},{"id":"T1595.003","name":"Wordlist Scanning","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Preventing information leakage through shared system resources limits the residual data (file paths, directory structures) available to adversaries performing wordlist-based scanning against shared web infrastructure."},{"id":"T1602.001","name":"SNMP (MIB Dump)","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Information remnance controls on shared management interfaces ensure SNMP query results and MIB data are securely cleared from shared memory, preventing recovery of residual configuration data."},{"id":"T1602.002","name":"Network Device Configuration Dump","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Preventing information persistence in shared device management resources ensures network device configuration dumps are securely cleared from shared storage after authorized use, eliminating residual configuration data."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: nist_csf_2 PR.DS-01, PR.DS-02, PR.IR-01 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base. 2026-10-03: baselines LMH to -MH, from NIST SP 800-53B Release 5.2.0.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-001","SP-002","SP-011","SP-013","SP-027","SP-047","SP-050"]}}