Compliance Node Overview
MITRE ATT&CK T0858 (Change Operating Mode) is an ATT&CK for ICS Execution and Evasion technique. Adversaries may change the operating mode of a controller to gain additional access to engineering functions such as Program Download. Programmable controllers typically have several modes of operation that control the state of the user program and control access to the controllers API. Operating modes can be physically selected using a key switch on the face of the controller but may also be selected with calls to the controllers API. Affected asset classes: None. MITRE-documented mitigations include M0802 Communication Authenticity, M0804 Human User Authentication, M0813 Software Process and Device Authentication, M0801 Access Management, M0807 Network Allowlists, M0930 Network Segmentation. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T0858/
SHA-256 integrity: 07a03452e5a9813d9ec09c6a55109376cf0879a450ec0766b7c833bf0b4d2999
Primary Citations — 7 traced to source
- MITRE ATT&CK for ICS Technique T0858: Change Operating Mode (https://attack.mitre.org/techniques/T0858/)
- MITRE ATT&CK ICS Tactic TA0104: Execution (https://attack.mitre.org/tactics/TA0104/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.