SA-24 — Design For Cyber Resiliency
Cyber resiliency is critical to ensuring the survivability of mission critical systems and high value assets. Cyber resiliency focuses on limiting the damage from adversity or the conditions that can cause a loss of assets. Damage can affect: (1) organizations (e.g., loss of reputation, increased existential risk); (2) missions or business functions (e.g., decreased capability to complete current missions and to accomplish future missions); (3) security (e.g., decreased capability to achieve security objectives or to prevent, detect, and respond to cyber incidents); (4) systems (e.g., unauthorized use of system resources or decreased capability to meet system requirements); or (5) specific system elements (e.g., physical destruction; corruption, modification, or fabrication of information). Cyber resiliency goals are intended to help organizations maintain a state of informed preparedne
Read the official statement, discussion, parameters, enhancements, and assessment methods →
NIST CSF 2.0 informative references
These CSF Subcategories list this base control or one of its enhancements in the imported NIST informative reference.
NIST SP 800-171 and SP 800-172
SP 800-171 requirements sourcing this control
SP 800-172 enhanced requirements sourcing this control
MITRE D3FEND techniques
MITRE ATT&CK relationships
Curated mitigation mappings
Inferred behavior relationships
Experimental: These relationships are inferred through D3FEND and must be validated against architecture, telemetry, and threat context.
Use the map without overclaiming.
A CSF informative reference is not an equivalence statement. A source-control relationship is not proof of implementation. A D3FEND semantic relationship is not a product claim. An inferred ATT&CK link is a hypothesis for engineering analysis.
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. Informative references and cross-framework relationships support navigation and analysis; they do not establish compliance, applicability, equivalence, control inheritance, or guaranteed mitigation effectiveness.