{"data":{"id":"SC-06","name":"Resource Availability","family":"SC","family_name":"System and Communications Protection","withdrawn":false,"description":"Protect the availability of resources by allocating [Assignment: organization-defined resources] by [Selection (one or more): priority; quota; [Assignment: organization-defined controls]].","supplemental_guidance":"Priority protection prevents lower-priority processes from delaying or interfering with the system that services higher-priority processes. Quotas prevent users or processes from obtaining more than predetermined amounts of resources.","enhancements":[],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"nist_800_53":{"rev5":{"id":"SC-06","name":"Resource Availability","description":"Protect the availability of resources by allocating [Assignment: organization-defined resources] by [Selection (one or more): priority; quota; [Assignment: organization-defined controls]].","discussion":"Priority protection prevents lower-priority processes from delaying or interfering with the system that services higher-priority processes. Quotas prevent users or processes from obtaining more than predetermined amounts of resources.","related_controls":["SC-05"],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":""}},"compliance_mappings":{"iso_27001_2022":["A.8.6"],"iso_27002_2022":[],"cobit_2019":[],"pci_dss_v4":[],"nist_csf_2":["PR.IR-03"],"cis_controls_v8":[],"soc2_tsc":["A1.1"],"finos_ccc":[],"iso_42001_2023":["A.4.5"],"iec_62443":["3-3 SR 7.2"],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":["Hygiene.23","SecNumCloud.13.3"],"osfi_b13":["B-13.2.6"],"finma_circular":["IV.A(28)","IV.A(29)"],"gdpr":["Art.32(1)(b)"],"dora":["Art.9(2)"],"bio2":[],"rbi_csf":[],"fisc":["FISC.O13"],"lgpd_bcb":[],"hkma_tme1":["TME1.5.3"],"mlps_2":[],"dnb_good_practice":[],"cra":["CRA.I.2h"],"swift_cscf":[],"cbb_tm":["TM-5"],"uae_ia":["T7"],"bcbs_239":["Principle 5"],"eba_ict":["3.5(a)"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":["CC Part 2 — FRU/FTA/FTP"],"isae_3402":[],"fca_sysc_13":["SYSC 13.7.2","SYSC 13.8.2"],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":[],"iso_27799":[],"lloyds_ms":[],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":[],"csa_ccm_v4":["IVS-02"],"csa_aicm":["I&S-02"],"ccss_v9":[],"mica":[],"basel_sco60":["SCO60.53"],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1564.009","name":"Resource Forking","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Resource priority mechanisms that limit alternate data stream and resource fork allocation prevent adversaries from consuming excessive storage through resource forking to hide large malicious payloads."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: nist_csf_2 PR.IR-03 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base. 2026-10-03: baselines LMH to ---, from NIST SP 800-53B Release 5.2.0.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-001","SP-002","SP-011"]}}