# SP-002 Server Module

Status: published. Release 26.02. Modified 2026-02-06. Licence: CC BY-SA 4.0.

Scope: Reusable security module defining the standard control baseline for server systems including physical, virtual, and cloud-hosted instances. Referenced as a building block by other OSA patterns wherever a server component appears in the architecture.
Use when: This module should be referenced by any OSA pattern that includes a server component in its architecture. It applies to physical servers, virtual machines, cloud instances (IaaS), and any system that provides services to other components rather than directly to end users.
Not when: This module is not designed for client endpoints (see SP-001 Client Module), mobile devices, or network infrastructure devices (routers, switches, firewalls) which have distinct management models and control requirements.

## Controls (90, NIST SP 800-53 ids)
- Critical (5): AC-03, AC-06, AU-02, AU-06, CM-02
- Important (37): AC-05, AC-07, AC-12, AU-03, AU-05, AU-08, AU-09, CA-07, CM-03, CM-04, CM-05, CM-06, CM-07, CM-08, CP-09, CP-10, IA-02, IR-04, IR-05, MA-04, PE-02, PE-03, PE-06, PE-11, PE-13, PE-14, RA-03, RA-05, SA-06, SC-02, SC-05, SC-12, SC-13, SI-02, SI-03, SI-04, SI-07
- Standard (48): AC-08, AC-09, AC-10, AT-03, AT-04, AU-04, AU-10, AU-11, CA-02, CA-04, CA-06, CP-03, CP-04, CP-05, IA-06, IA-07, IR-02, IR-03, IR-06, IR-07, MA-02, MA-03, MA-05, MA-06, MP-02, PE-05, PE-09, PE-10, PE-12, PE-15, PE-16, RA-02, RA-04, SA-02, SA-03, SA-04, SA-05, SA-08, SC-03, SC-04, SC-06, SC-10, SC-14, SC-18, SI-05, SI-06, SI-10, SI-11
- Withdrawn from SP 800-53 by NIST: CA-04 (now in CA-02); CP-05 (now in CP-02); RA-04 (now in RA-03); SA-06 (now in CM-10, SI-07); SC-14 (now in AC-02, AC-03, AC-05, AC-06, SI-03, SI-04, SI-05, SI-07, SI-10)

## What each critical control mitigates (5)
- AC-03 Access Enforcement: T-SM-002
- AC-06 Least Privilege: T-SM-002
- AU-02 Event Logging: T-SM-004
- AU-06 Audit Record Review, Analysis, and Reporting: T-SM-003, T-SM-004
- CM-02 Baseline Configuration: T-SM-008

## Threats and the controls that mitigate them (10)
- T-SM-001 Remote Exploitation of Unpatched Server Vulnerabilities: RA-05, SI-02, SI-05, CM-07
- T-SM-002 Privilege Escalation and Lateral Movement: AC-06, AC-05, AC-03, SC-02
- T-SM-003 Unauthorised Administrative Access: AC-07, IA-02, AC-10, AU-06
- T-SM-004 Data Exfiltration from Server-Hosted Repositories: AU-02, AU-06, SI-04, IR-05, SC-13
- T-SM-005 Ransomware and Destructive Malware Attack: SI-03, CP-09, CP-10, SI-07, CM-07
- T-SM-006 Physical Compromise and Hardware Theft: PE-02, PE-03, PE-06, SC-12, SC-13
- T-SM-007 Environmental Failure (Power, Cooling, Fire, Water): PE-09, PE-10, PE-11, PE-13, PE-14, PE-15
- T-SM-008 Configuration Drift and Unauthorised System Changes: CM-02, CM-03, CM-04, CM-06, CA-07
- T-SM-009 Supply Chain Compromise and Software Integrity Tampering: SI-07, SA-04, SA-08, SI-06
- T-SM-010 Audit Log Evasion and Forensic Evidence Destruction: AU-09, AU-05, AU-11, AU-10

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-002/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-002/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 32 KB: /api/v1/patterns/SP-002
- Page for people: /patterns/sp-002/
- Related: SP-001 Client Module; SP-008 Public Web Server Pattern; SP-011 Cloud Computing Pattern; SP-013 Data Security Pattern; SP-016 DMZ Module; SP-018 Information Security Management System; SP-023 Industrial Control Systems; SP-025 Advanced Monitoring and Detection; SP-026 PCI Full Environment

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
