Compliance Node Overview
MITRE ATT&CK T0889 (Modify Program) is an ATT&CK for ICS Persistence technique. Adversaries may modify or add a program on a controller to affect how it interacts with the physical process, peripheral devices and other hosts on the network. Modification to controller programs can be accomplished using a Program Download in addition to other types of program modification such as online edit and program append. Affected asset classes: None. MITRE-documented mitigations include M0947 Audit, M0945 Code Signing, M0800 Authorization Enforcement, M0804 Human User Authentication. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T0889/
SHA-256 integrity: 1f9bc1a5bf3e327374b3c782add35a3512b2ed8db10981ca6ceafde5d6221ef9
Primary Citations — 7 traced to source
- MITRE ATT&CK for ICS Technique T0889: Modify Program (https://attack.mitre.org/techniques/T0889/)
- MITRE ATT&CK ICS Tactic TA0110: Persistence (https://attack.mitre.org/tactics/TA0110/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.