id: "SC-26" title: "Decoys" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-26" priority: "P1" implementation_level: "system" enhancements: - sc-26.1


Statement

Include components within organizational systems specifically designed to be the target of malicious attacks for detecting, deflecting, and analyzing such attacks.

Guidance

Decoys (i.e., honeypots, honeynets, or deception nets) are established to attract adversaries and deflect attacks away from the operational systems that support organizational mission and business functions. Use of decoys requires some supporting isolation measures to ensure that any deflected malicious code does not infect organizational systems. Depending on the specific usage of the decoy, consultation with the Office of the General Counsel before deployment may be needed.

Assessment Objective: components within organizational systems specifically designed to be the target of malicious attacks are included to detect such attacks;

Assessment Objective: components within organizational systems specifically designed to be the target of malicious attacks are included to deflect such attacks;

Assessment Objective: components within organizational systems specifically designed to be the target of malicious attacks are included to analyze such attacks.

System and communications protection policy

procedures addressing the use of decoys

system design documentation

system configuration settings and associated documentation

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

system developer

Mechanisms supporting and/or implementing decoys