{"data":{"id":"SC-18","name":"Mobile Code","family":"SC","family_name":"System and Communications Protection","withdrawn":false,"description":"a. Define acceptable and unacceptable mobile code and mobile code technologies; and\nb. Authorize, monitor, and control the use of mobile code within the system.","supplemental_guidance":"Mobile code includes any program, application, or content that can be transmitted across a network (e.g., embedded in an email, document, or website) and executed on a remote system. Decisions regarding the use of mobile code within organizational systems are based on the potential for the code to cause damage to the systems if used maliciously. Mobile code technologies include Java applets, JavaScript, HTML5, WebGL, and VBScript. Usage restrictions and implementation guidelines apply to both the selection and use of mobile code installed on servers and mobile code downloaded and executed on individual workstations and devices, including notebook computers and smart phones. Mobile code policy and procedures address specific actions taken to prevent the development, acquisition, and introduction of unacceptable mobile code within organizational systems, including requiring mobile code to be digitally signed by a trusted source.","enhancements":[{"id":"SC-18(01)","name":"Identify Unacceptable Code and Take Corrective Actions","statement":"Identify [Assignment: organization-defined unacceptable mobile code] and take [Assignment: organization-defined corrective actions].","baselines":[]},{"id":"SC-18(02)","name":"Acquisition, Development, and Use","statement":"Verify that the acquisition, development, and use of mobile code to be deployed in the system meets [Assignment: organization-defined mobile code requirements].","baselines":[]},{"id":"SC-18(03)","name":"Prevent Downloading and Execution","statement":"Prevent the download and execution of [Assignment: organization-defined unacceptable mobile code].","baselines":[]},{"id":"SC-18(04)","name":"Prevent Automatic Execution","statement":"Prevent the automatic execution of mobile code in [Assignment: organization-defined software applications] and enforce [Assignment: organization-defined actions] prior to executing the code.","baselines":[]},{"id":"SC-18(05)","name":"Allow Execution Only in Confined Environments","statement":"Allow execution of permitted mobile code only in confined virtual machine environments.","baselines":[]}],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"SC-18","name":"Mobile Code","description":"a. Define acceptable and unacceptable mobile code and mobile code technologies; and\nb. Authorize, monitor, and control the use of mobile code within the system.","discussion":"Mobile code includes any program, application, or content that can be transmitted across a network (e.g., embedded in an email, document, or website) and executed on a remote system. Decisions regarding the use of mobile code within organizational systems are based on the potential for the code to cause damage to the systems if used maliciously. Mobile code technologies include Java applets, JavaScript, HTML5, WebGL, and VBScript. Usage restrictions and implementation guidelines apply to both the selection and use of mobile code installed on servers and mobile code downloaded and executed on individual workstations and devices, including notebook computers and smart phones. Mobile code policy and procedures address specific actions taken to prevent the development, acquisition, and introduction of unacceptable mobile code within organizational systems, including requiring mobile code to be digitally signed by a trusted source.","related_controls":["AU-02","AU-12","CM-02","CM-06","SI-03"],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"Control text replaces requirement to establish usage restrictions and implementation guidance with requirement to authorize, monitor, and control the use of mobile code within the system Discussion expanded with additional examples of mobile code and factors that should be included in mobile code policy and procedures"}},"compliance_mappings":{"iso_27001_2022":[],"iso_27002_2022":[],"cobit_2019":[],"pci_dss_v4":[],"nist_csf_2":[],"cis_controls_v8":["CIS 9","CIS 9.6"],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":["3-3 SR 2.4"],"asd_e8":["E8-3","E8-3 ML2","E8-4","E8-4 ML1"],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":["APP.1.1"],"anssi":["Hygiene.20","Hygiene.22","SecNumCloud.13.1"],"osfi_b13":["B-13.3.2"],"finma_circular":["IV.B.d(59)","IV.C(64)"],"gdpr":["Art.32(1)(b)"],"dora":["Art.9(4)(e)"],"bio2":[],"rbi_csf":["Annex1.2"],"fisc":["FISC.T8"],"lgpd_bcb":[],"hkma_tme1":["TME1.10.2"],"mlps_2":[],"dnb_good_practice":["DNB.19.1"],"cra":[],"swift_cscf":[],"nca_ecc":["2-3"],"ffiec_is":["II.C.12"],"sebi_cscrf":["PR.ES"],"cmmc_2":["SC"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":[],"iso_27799":[],"lloyds_ms":["MS8.10"],"naic_ds":[],"nhs_dspt":["NDG-9.3","NDG-9.5"],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":["MASVS-CODE-4"],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1055","name":"Process Injection","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Mobile code restrictions that control which active content technologies can execute within the system—blocking unsigned applets, restricting plugin capabilities—limit the vectors available for process injection through mobile code execution contexts."},{"id":"T1059","name":"Command and Scripting Interpreter","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Usage restrictions on mobile code technologies directly limit the scripting engines and active content interpreters (JavaScript, VBScript, Java) available for adversary command execution within the information system."},{"id":"T1068","name":"Exploitation for Privilege Escalation","tactics":["privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Mobile code controls that restrict execution of untrusted active content and enforce sandboxing of code execution environments reduce the exploitable surface available for privilege escalation through mobile code vulnerability exploitation."},{"id":"T1137","name":"Office Application Startup","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Restricting mobile code execution within Office applications—blocking macros, ActiveX controls, and external content loading—prevents adversaries from establishing persistence through Office startup mechanisms that rely on active content."},{"id":"T1189","name":"Drive-by Compromise","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Mobile code restrictions that block or sandbox active content (Java, Flash, JavaScript) from untrusted sources directly reduce the attack surface for drive-by compromise by limiting which executable content can run in the browser."},{"id":"T1190","name":"Exploit Public-Facing Application","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Controls on mobile code technologies in web applications—restricting server-side active content, enforcing input validation on dynamic content—reduce exploitable vulnerabilities in public-facing application mobile code processing."},{"id":"T1203","name":"Exploitation for Client Execution","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Mobile code restrictions that disable unnecessary browser plugins, enforce content security policies, and sandbox active content execution directly mitigate exploitation for client execution through malicious mobile code payloads."},{"id":"T1210","name":"Exploitation of Remote Services","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Restricting mobile code execution on network-accessible services limits the attack surface for exploitation of remote services through malicious active content delivered via network communications."},{"id":"T1211","name":"Exploitation for Defense Evasion","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Mobile code controls that enforce content execution policies and sandbox active content reduce the attack surface for exploitation techniques that target defense evasion through mobile code processing vulnerabilities."},{"id":"T1212","name":"Exploitation for Credential Access","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Restricting mobile code technologies limits the exploitable interfaces available for credential access through vulnerabilities in active content processing engines and browser plugin credential handling."},{"id":"T1548","name":"Abuse Elevation Control Mechanism","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Mobile code controls that restrict active content from invoking elevation prompts or accessing privileged APIs prevent mobile code-based exploitation of elevation control mechanisms for privilege escalation."},{"id":"T1559","name":"Inter-Process Communication","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Restricting mobile code technologies that leverage inter-process communication—COM objects, DDE, ActiveX—prevents adversaries from using mobile code to trigger unauthorized inter-process command execution."},{"id":"T1021.003","name":"Distributed Component Object Model","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Mobile code restrictions on DCOM execution within active content contexts prevent adversaries from using mobile code technologies to invoke Distributed Component Object Model for lateral movement."},{"id":"T1055.001","name":"Dynamic-link Library Injection","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Mobile code controls that restrict DLL injection capabilities within active content execution contexts prevent adversaries from using mobile code to perform dynamic-link library injection into target processes."},{"id":"T1055.002","name":"Portable Executable Injection","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Restricting mobile code from accessing process memory injection APIs prevents adversaries from using active content technologies to perform portable executable injection into running processes."},{"id":"T1055.003","name":"Thread Execution Hijacking","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Mobile code sandboxing that isolates active content from thread manipulation APIs prevents adversaries from using mobile code to perform thread execution hijacking in legitimate processes."},{"id":"T1055.004","name":"Asynchronous Procedure Call","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Mobile code restrictions that prevent access to asynchronous procedure call queuing mechanisms limit adversaries' ability to use active content for APC-based code injection into target processes."},{"id":"T1055.005","name":"Thread Local Storage","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Restricting mobile code access to thread local storage manipulation APIs prevents adversaries from using active content technologies to perform TLS-based code injection in legitimate processes."},{"id":"T1055.008","name":"Ptrace System Calls","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Mobile code controls that restrict debugging capabilities within active content execution environments prevent adversaries from using mobile code to perform ptrace-based process injection on Linux systems."},{"id":"T1055.009","name":"Proc Memory","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Restricting mobile code access to /proc memory interfaces prevents adversaries from using active content technologies to read and write process memory for code injection on Linux systems."},{"id":"T1055.011","name":"Extra Window Memory Injection","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Mobile code controls that prevent access to window memory manipulation APIs restrict adversaries from using active content to perform extra window memory injection techniques in Windows environments."},{"id":"T1055.012","name":"Process Hollowing","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Mobile code sandboxing that isolates active content from process creation and memory mapping APIs prevents adversaries from using mobile code to perform process hollowing of legitimate executables."},{"id":"T1055.013","name":"Process Doppelgänging","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Restricting mobile code access to NTFS transaction APIs and process creation interfaces prevents adversaries from using active content to perform process doppelganging attacks that evade security tools."},{"id":"T1055.014","name":"VDSO Hijacking","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Mobile code controls that prevent access to virtual dynamic shared object memory regions limit adversaries' ability to use active content for VDSO hijacking on Linux systems."},{"id":"T1059.005","name":"Visual Basic","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Mobile code restrictions that disable VBScript execution in browsers and email clients through Windows Script Host controls prevent adversaries from executing malicious Visual Basic mobile code payloads."},{"id":"T1059.007","name":"JavaScript","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Restricting JavaScript execution contexts—enforcing content security policies, disabling eval(), limiting Web Worker capabilities—prevents adversaries from abusing JavaScript as a mobile code execution vector."},{"id":"T1127.002","name":"ClickOnce","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Mobile code controls that restrict ClickOnce application deployment from untrusted zones prevent adversaries from using ClickOnce mobile code technology to proxy execution of malicious .NET payloads."},{"id":"T1137.001","name":"Office Template Macros","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Restricting mobile code in Office template macros—blocking VBA execution from untrusted sources and enforcing signed macro policies—prevents adversaries from using template-based mobile code for persistence."},{"id":"T1137.002","name":"Office Test","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Mobile code controls that restrict DLL loading through Office Test registry mechanisms prevent adversaries from using the Office Test mobile code loading path for persistent code execution."},{"id":"T1137.003","name":"Outlook Forms","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Restricting mobile code execution within Outlook custom forms prevents adversaries from deploying malicious active content through Outlook Forms for persistent code execution in the email client."},{"id":"T1137.004","name":"Outlook Home Page","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Mobile code controls that disable Outlook Home Page functionality or restrict its content sources prevent adversaries from embedding malicious HTML/JavaScript mobile code in Outlook folder views."},{"id":"T1137.005","name":"Outlook Rules","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Restricting mobile code capabilities within Outlook rules—disabling rules that invoke applications or scripts—prevents adversaries from establishing persistent rule-triggered mobile code execution."},{"id":"T1137.006","name":"Add-ins","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Mobile code controls that restrict Office add-in installation to trusted, signed packages prevent adversaries from deploying malicious add-in mobile code for persistent execution within Office applications."},{"id":"T1218.001","name":"Compiled HTML File","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Restricting mobile code execution through compiled HTML (CHM) files by blocking hh.exe or limiting CHM content sources prevents adversaries from using CHM-embedded mobile code for defense evasion."},{"id":"T1218.015","name":"Electron Applications","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Mobile code controls that restrict Electron application execution prevent adversaries from abusing Electron's embedded Chromium and Node.js mobile code runtime for defense evasion and code execution."},{"id":"T1548.004","name":"Elevated Execution with Prompt","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Restricting mobile code from invoking system elevation prompts on macOS prevents adversaries from using active content to trigger authorization dialogs that trick users into granting elevated permissions."},{"id":"T1559.001","name":"Component Object Model","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Mobile code restrictions that limit COM object instantiation within active content contexts prevent adversaries from using mobile code to invoke Component Object Model for inter-process code execution."},{"id":"T1559.002","name":"Dynamic Data Exchange","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Restricting Dynamic Data Exchange capabilities in mobile code contexts—disabling DDE auto-update and OLE links in active content—prevents adversaries from using DDE-based mobile code for code execution."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: baselines LMH to -MH, from NIST SP 800-53B Release 5.2.0.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-001","SP-002","SP-011"]}}