Control statement
Employ the following concealment and misdirection techniques for [Organization-defined: systems] at [Organization-defined: time periods] to confuse and mislead adversaries: [Organization-defined: concealment and misdirection techniques].
Discussion
Concealment and misdirection techniques can significantly reduce the targeting capabilities of adversaries (i.e., window of opportunity and available attack surface) to initiate and complete attacks. For example, virtualization techniques provide organizations with the ability to disguise systems, potentially reducing the likelihood of successful attacks without the cost of having multiple platforms. The increased use of concealment and misdirection techniques and methods—including randomness, uncertainty, and virtualization—may sufficiently confuse and mislead adversaries and subsequently increase the risk of discovery and/or exposing tradecraft. Concealment and misdirection techniques may provide additional time to perform core mission and business functions. The implementation of concealment and misdirection techniques may add to the complexity and management overhead required for the system.
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use Concealment and Misdirection as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to secure architecture, boundary protection, communications protection, cryptography, and system isolation.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- network and trust-boundary diagrams
- firewall and gateway configurations
- cryptographic configuration and key records
- segmentation and isolation test results
Common failure patterns
- diagrams omit cloud and third-party paths
- encryption enabled without key governance
- flat trust zones allow unnecessary lateral movement
- boundary rules accumulate without owner review
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
[Organization-defined: concealment and misdirection techniques] are employed for [Organization-defined: systems] for [Organization-defined: time periods] to confuse and mislead adversaries.
Examine
- System and communications protection policy
- procedures addressing concealment and misdirection techniques for the system
- system design documentation
- system configuration settings and associated documentation
- system architecture
- list of concealment and misdirection techniques to be employed for organizational systems
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- organizational personnel with the responsibility to implement concealment and misdirection techniques for systems
Test
- Mechanisms supporting and/or implementing concealment and misdirection techniques
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Related NIST SP 800-172 requirements
These Rev. 3 requirements cite this base control or one of its enhancements as a source. The relationship does not by itself determine contractual applicability or complete implementation.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
SC-30(1) — Virtualization Techniques
This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.
SC-30(2) — Randomness
Employ [Organization-defined: techniques] to introduce randomness into organizational operations and assets.
Official discussion
Randomness introduces increased levels of uncertainty for adversaries regarding the actions that organizations take to defend their systems against attacks. Such actions may impede the ability of adversaries to correctly target information resources of organizations that support critical missions or business functions. Uncertainty may also cause adversaries to hesitate before initiating or continuing attacks. Misdirection techniques that involve randomness include performing certain routine actions at different times of day, employing different information technologies, using different suppliers, and rotating roles and responsibilities of organizational personnel.
Organization-defined parameters (1)
Assessment objectives and methods
[Organization-defined: techniques] are employed to introduce randomness into organizational operations and assets.
Examine
- System and communications protection policy
- procedures addressing concealment and misdirection techniques for the system
- system design documentation
- system configuration settings and associated documentation
- system architecture
- list of techniques to be employed to introduce randomness into organizational operations and assets
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- organizational personnel with the responsibility to implement concealment and misdirection techniques for systems
Test
- Mechanisms supporting and/or implementing randomness as a concealment and misdirection technique
SC-30(3) — Change Processing and Storage Locations
Change the location of [Organization-defined: processing and/or storage] [Organization-defined: sc-30.03_odp.02]].
Official discussion
Adversaries target critical mission and business functions and the systems that support those mission and business functions while also trying to minimize the exposure of their existence and tradecraft. The static, homogeneous, and deterministic nature of organizational systems targeted by adversaries make such systems more susceptible to attacks with less adversary cost and effort to be successful. Changing processing and storage locations (also referred to as moving target defense) addresses the advanced persistent threat using techniques such as virtualization, distributed processing, and replication. This enables organizations to relocate the system components (i.e., processing, storage) that support critical mission and business functions. Changing the locations of processing activities and/or storage sites introduces a degree of uncertainty into the targeting activities of adversaries. The targeting uncertainty increases the work factor of adversaries and makes compromises or breaches of the organizational systems more difficult and time-consuming. It also increases the chances that adversaries may inadvertently disclose certain aspects of their tradecraft while attempting to locate critical organizational resources.
Organization-defined parameters (3)
Assessment objectives and methods
the location of [Organization-defined: processing and/or storage] is changed [Organization-defined: sc-30.03_odp.02].
Examine
- System and communications protection policy
- configuration management policy and procedures
- procedures addressing concealment and misdirection techniques for the system
- list of processing/storage locations to be changed at organizational time intervals
- change control records
- configuration management records
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- organizational personnel with the responsibility to change processing and/or storage locations
Test
- Mechanisms supporting and/or implementing changing processing and/or storage locations
SC-30(4) — Misleading Information
Employ realistic, but misleading information in [Organization-defined: system components] about its security state or posture.
Official discussion
Employing misleading information is intended to confuse potential adversaries regarding the nature and extent of controls deployed by organizations. Thus, adversaries may employ incorrect and ineffective attack techniques. One technique for misleading adversaries is for organizations to place misleading information regarding the specific controls deployed in external systems that are known to be targeted by adversaries. Another technique is the use of deception nets that mimic actual aspects of organizational systems but use, for example, out-of-date software configurations.
Organization-defined parameters (1)
Assessment objectives and methods
realistic but misleading information about the security state or posture of [Organization-defined: system components] is employed.
Examine
- System and communications protection policy
- configuration management policy and procedures
- procedures addressing concealment and misdirection techniques for the system
- system design documentation
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- organizational personnel with the responsibility to define and employ realistic but misleading information about the security posture of system components
Test
- Mechanisms supporting and/or implementing the employment of realistic but misleading information about the security posture of system components
SC-30(5) — Concealment of System Components
Employ the following techniques to hide or conceal [Organization-defined: system components]: [Organization-defined: techniques].
Official discussion
By hiding, disguising, or concealing critical system components, organizations may be able to decrease the probability that adversaries target and successfully compromise those assets. Potential means to hide, disguise, or conceal system components include the configuration of routers or the use of encryption or virtualization techniques.
Organization-defined parameters (2)
Assessment objectives and methods
[Organization-defined: techniques] are employed to hide or conceal [Organization-defined: system components].
Examine
- System and communications protection policy
- configuration management policy and procedures
- procedures addressing concealment and misdirection techniques for the system
- system design documentation
- system configuration settings and associated documentation
- list of techniques employed to hide or conceal system components
- list of system components to be hidden or concealed
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- organizational personnel with the responsibility to conceal system components
Test
- Mechanisms supporting and/or implementing techniques for the concealment of system components
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.