Control statement
- a.Perform a covert channel analysis to identify those aspects of communications within the system that are potential avenues for covert [Organization-defined: sc-31_odp] channels; and
- b.Estimate the maximum bandwidth of those channels.
Discussion
Developers are in the best position to identify potential areas within systems that might lead to covert channels. Covert channel analysis is a meaningful activity when there is the potential for unauthorized information flows across security domains, such as in the case of systems that contain export-controlled information and have connections to external networks (i.e., networks that are not controlled by organizations). Covert channel analysis is also useful for multilevel secure systems, multiple security level systems, and cross-domain systems.
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use Covert Channel Analysis as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to secure architecture, boundary protection, communications protection, cryptography, and system isolation.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- network and trust-boundary diagrams
- firewall and gateway configurations
- cryptographic configuration and key records
- segmentation and isolation test results
Common failure patterns
- diagrams omit cloud and third-party paths
- encryption enabled without key governance
- flat trust zones allow unnecessary lateral movement
- boundary rules accumulate without owner review
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- SC-31a.a covert channel analysis is performed to identify those aspects of communications within the system that are potential avenues for covert [Organization-defined: sc-31_odp] channels;
- SC-31b.the maximum bandwidth of those channels is estimated.
Examine
- System and communications protection policy
- procedures addressing covert channel analysis
- system design documentation
- system configuration settings and associated documentation
- covert channel analysis documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- organizational personnel with covert channel analysis responsibilities
- system developers/integrators
Test
- Organizational process for conducting covert channel analysis
- mechanisms supporting and/or implementing covert channel analysis
- mechanisms supporting and/or implementing the capability to estimate the bandwidth of covert channels
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
SC-31(1) — Test Covert Channels for Exploitability
Test a subset of the identified covert channels to determine the channels that are exploitable.
Official discussion
None.
Assessment objectives and methods
a subset of the identified covert channels is tested to determine the channels that are exploitable.
Examine
- System and communications protection policy
- procedures addressing covert channel analysis
- system design documentation
- system configuration settings and associated documentation
- list of covert channels
- covert channel analysis documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- organizational personnel with covert channel analysis responsibilities
Test
- Organizational process for testing covert channels
- mechanisms supporting and/or implementing the testing of covert channel analysis
SC-31(2) — Maximum Bandwidth
Reduce the maximum bandwidth for identified covert [Organization-defined: sc-31.02_odp.01] channels to [Organization-defined: values].
Official discussion
The complete elimination of covert channels, especially covert timing channels, is usually not possible without significant performance impacts.
Organization-defined parameters (2)
Assessment objectives and methods
the maximum bandwidth for identified covert [Organization-defined: sc-31.02_odp.01] channels is reduced to [Organization-defined: values].
Examine
- System and communications protection policy
- procedures addressing covert channel analysis
- acquisition contracts for systems or services
- acquisition documentation
- system design documentation
- system configuration settings and associated documentation
- covert channel analysis documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- organizational personnel with covert channel analysis responsibilities
- system developers/integrators
Test
- Organizational process for conducting covert channel analysis
- mechanisms supporting and/or implementing covert channel analysis
- mechanisms supporting and/or implementing the capability to reduce the bandwidth of covert channels
SC-31(3) — Measure Bandwidth in Operational Environments
Measure the bandwidth of [Organization-defined: subset of identified covert channels] in the operational environment of the system.
Official discussion
Measuring covert channel bandwidth in specified operational environments helps organizations determine how much information can be covertly leaked before such leakage adversely affects mission or business functions. Covert channel bandwidth may be significantly different when measured in settings that are independent of the specific environments of operation, including laboratories or system development environments.
Organization-defined parameters (1)
Assessment objectives and methods
the bandwidth of [Organization-defined: subset of identified covert channels] is measured in the operational environment of the system.
Examine
- System and communications protection policy
- procedures addressing covert channel analysis
- system design documentation
- system configuration settings and associated documentation
- covert channel analysis documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- organizational personnel with covert channel analysis responsibilities
- system developers/integrators
Test
- Organizational process for conducting covert channel analysis
- mechanisms supporting and/or implementing covert channel analysis
- mechanisms supporting and/or implementing the capability to measure the bandwidth of covert channels
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.