# SP-001 Client Module

Status: published. Release 26.02. Modified 2026-02-06. Licence: CC BY-SA 4.0.

Scope: Reusable security module defining the standard control baseline for client endpoints including desktops, laptops, and workstations. Referenced as a building block by other OSA patterns wherever a client device appears in the architecture.
Use when: This module should be referenced by any OSA pattern that includes a client endpoint device in its architecture. It applies to corporate desktops and laptops, developer workstations, kiosk systems, shared terminals, and any user-facing computing device that processes, stores, or transmits organisational data.
Not when: This module is not designed for mobile devices (phones, tablets) which have fundamentally different OS architectures, management models, and threat profiles -- see the Mobile Device patterns instead.

## Controls (80, NIST SP 800-53 ids)
- Critical (5): AC-03, AC-06, AU-02, CM-02, CM-07
- Important (26): AC-07, AC-11, AC-12, AU-03, AU-08, AU-09, CA-07, CM-03, CM-04, CM-05, CM-06, CM-08, CP-09, IA-02, IR-04, IR-05, RA-03, RA-05, SA-06, SA-07, SC-12, SC-13, SI-02, SI-03, SI-04, SI-07
- Standard (49): AC-05, AC-08, AC-19, AT-02, AT-03, AT-04, AU-04, AU-05, AU-10, AU-11, CA-02, CA-04, CA-06, CP-03, CP-04, CP-05, CP-10, IA-06, IA-07, IR-02, IR-03, IR-06, IR-07, MA-02, MA-03, MA-04, MA-05, MA-06, MP-02, PL-04, PS-06, RA-02, RA-04, SA-02, SA-03, SA-04, SA-05, SA-08, SC-03, SC-04, SC-05, SC-06, SC-11, SC-14, SC-15, SC-18, SI-05, SI-06, SI-11
- Withdrawn from SP 800-53 by NIST: CA-04 (now in CA-02); CP-05 (now in CP-02); RA-04 (now in RA-03); SA-06 (now in CM-10, SI-07); SA-07 (now in CM-11, SI-07); SC-14 (now in AC-02, AC-03, AC-05, AC-06, SI-03, SI-04, SI-05, SI-07, SI-10)

## What each critical control mitigates (5)
- AC-03 Access Enforcement: T-CM-004
- AC-06 Least Privilege: T-CM-004, T-CM-006
- AU-02 Event Logging: T-CM-006
- CM-02 Baseline Configuration: T-CM-003, T-CM-007
- CM-07 Least Functionality: T-CM-001

## Threats and the controls that mitigate them (10)
- T-CM-001 Malware Infection via Phishing or Drive-By Download: SI-03, CM-07, SA-06, SA-07, SI-07
- T-CM-002 Credential Theft and Brute-Force Authentication Attack: AC-07, IA-02, AC-11, SC-13
- T-CM-003 Exploitation of Unpatched Software Vulnerabilities: RA-05, SI-02, SI-05, CM-02
- T-CM-004 Unauthorised Data Access and Privilege Escalation: AC-03, AC-06, AC-05, CM-05
- T-CM-005 Data Loss from Device Theft or Physical Compromise: SC-12, SC-13, MP-02, SC-04
- T-CM-006 Insider Threat and Unauthorised Activity: AU-02, AU-03, SI-04, AC-06, PL-04
- T-CM-007 Configuration Drift and Baseline Deviation: CM-02, CM-03, CM-04, CM-06, CA-07
- T-CM-008 Session Hijacking and Unattended Workstation Abuse: AC-11, AC-12, SC-11, AU-10
- T-CM-009 Supply Chain Compromise and Software Integrity Tampering: SI-07, SA-04, SA-08, SI-06
- T-CM-010 Audit Log Tampering and Evidence Destruction: AU-09, AU-04, AU-05, AU-11

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-001/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-001/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 27 KB: /api/v1/patterns/SP-001
- Page for people: /patterns/sp-001/
- Related: SP-002 Server Module; SP-006 Wireless Private Network Pattern; SP-007 Wireless Public Hotspot Pattern; SP-008 Public Web Server Pattern; SP-011 Cloud Computing Pattern; SP-014 Awareness and Training Pattern; SP-016 DMZ Module; SP-024 iPhone Pattern; SP-025 Advanced Monitoring and Detection

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
