STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← All Controls

SC-30

System and Communications ProtectionRev 5organization

Concealment and Misdirection

Control Statement

Employ the following concealment and misdirection techniques for [Assignment: systems] at [Assignment: time periods] to confuse and mislead adversaries: [Assignment: concealment and misdirection techniques].

Supplemental Guidance

Concealment and misdirection techniques can significantly reduce the targeting capabilities of adversaries (i.e., window of opportunity and available attack surface) to initiate and complete attacks. For example, virtualization techniques provide organizations with the ability to disguise systems, potentially reducing the likelihood of successful attacks without the cost of having multiple platforms. The increased use of concealment and misdirection techniques and methods—including randomness, uncertainty, and virtualization—may sufficiently confuse and mislead adversaries and subsequently increase the risk of discovery and/or exposing tradecraft. Concealment and misdirection techniques may provide additional time to perform core mission and business functions. The implementation of concealment and misdirection techniques may add to the complexity and management overhead required for the system.

Related Controls (6)

AC-6SC-25SC-26SC-29SC-44SI-14

CCI Identifiers (5)

CCI-001202The organization employs virtualization techniques to present information system components as other types of components, or components with differing configurations.CCI-002482Defines the concealment and misdirection techniques employed for organization-defined systems to confuse and mislead adversaries.CCI-002483Defines the systems for which organization-defined concealment and misdirection techniques are to be employed.CCI-002484Defines the time periods at which to employ organization-defined concealment and misdirection techniques on organization-defined systems.CCI-002485Employ organization-defined concealment and misdirection techniques for organization-defined systems at organization-defined time periods to confuse and mislead adversaries.

Linked STIG Checks (0)

No STIG checks reference this control.