Command and Control
What is Command and Control?
The infrastructure and communication channels used by attackers to maintain remote control over compromised systems within a target network.
Terms that appear alongside command and control
Each of these is named in at least one of the same controls as command and control. The number is how many controls name both.
- cybersecurity 3 shared controls
- threat hunting 2 shared controls
- mitre 2 shared controls
- cisa 2 shared controls
- incident response 2 shared controls
- governance 2 shared controls
Frameworks that govern command and control
What the standards actually require on command and control
Requirements naming command and control across 6 standards, quoted from the control text.
Alternate Communications Paths. Establish [organization-defined] for system operations organizational command and control
NIST800-SC-47 · Alternate Communications Paths. Establish [organization-defined] for system operations organizational command and control →Unmanned Aircraft Systems (UAS) cybersecurity is governed through: (a) 14 CFR Part 107 (small UAS rule) including operational restrictions + remote pilot certification;
FAA-CSA-UAS-Drone · Unmanned Aircraft Systems (UAS / Drones) Cybersecurity →44 USC 3556 - Federal Information Security Incident Center (FedCIRC, now CISA US-CERT). The CISA Director operates the federal information security incident center providing: (a) timely warnings on emerging threats;
FISMA-3556-FederalCIRC-3557-NSS · Federal Information Security Incident Center (44 USC 3556) + National Security Systems Exclusion (44 USC 3557) →Coordinate command and control across multiple agencies through unified or joint command structures as appropriate.
ISO22320-8.2 · Multi Agency Coordination →X.805 Clause 8 defines 5 Threat Categories that the X.805 Security Architecture is designed to mitigate + provides a Threat-Dimension Countermeasure Matrix linking each threat to specific Dimensions.
X805-Threats-Destruction-Corruption-Removal-Disclosure-Interruption-72Cell-Matrix-Application · ITU-T X.805 5 Threat Categories - Destruction + Corruption + Removal + Disclosure + Interruption + Threat-Dimension Countermeasure Matrix + 72-Cell Matrix Application + STRIDE + MITRE ATT and CK + Network Modular Risk Assessment →Continuous security monitoring + 24x7 SOC operations are expected per FSA Cybersecurity Guidelines particularly for Tier 2/3 institutions. (1) SOC Operating Models: (a) Internal SOC - dedicated team + tooling;
JP-FSA-CYB-Security-Monitoring-SOC-Operations-SIEM-EDR-MDR-XDR-24x7-Detection-Alert-Triage · Japan FSA Cybersecurity Security Monitoring + SOC 24x7 Operations + SIEM + EDR + MDR + XDR + Detection + Alert Triage + Threat Hunting + Incident Response Integration + Threat Intelligence Integration + UEBA →Questions people ask about command and control
What is Command and Control?
Why is Command and Control important for compliance?
Which compliance frameworks address Command and Control?
Where can I learn more about Command and Control?
See how Command and Control applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.