# SI-16 — Memory Protection

- **Control ID:** SI-16
- **Family:** [SI](/md/families/SI.md)
- **Baselines:** moderate, high
- **Enhancement of:** No content available.

## Description

Implement the following controls to protect the system memory from unauthorized code execution: \[assignment\].

## Discussion

Some adversaries launch attacks with the intent of executing code in non-executable regions of memory or in memory locations that are prohibited. Controls employed to protect memory include data execution prevention and address space layout randomization. Data execution prevention controls can either be hardware-enforced or software-enforced with hardware enforcement providing the greater strength of mechanism.

## Implementation guidance

No content available.

## CSF 2.0 subcategories

- [PR.DS-10](/md/csf/PR.DS-10.md) — PR.DS-10

## Related controls

- [AC-25](/md/controls/AC-25.md)
- [SC-3](/md/controls/SC-3.md)
- [SI-7](/md/controls/SI-7.md)

---

Derived from official NIST publications (NIST SP 800-53 Rev 5 and NIST CSF 2.0). nistcontrols.com is not affiliated with NIST.
