Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

SC-31 — Covert Channel Analysis

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

3Enhancements
1Parameters
0Baseline memberships
3Assessment methods

SC — System and Communications Protection · NIST SP 800-53 Release 5.2.0

Official NIST control content

Control statement

  1. a.Perform a covert channel analysis to identify those aspects of communications within the system that are potential avenues for covert [Organization-defined: sc-31_odp] channels; and
  2. b.Estimate the maximum bandwidth of those channels.
Official NIST discussion

Discussion

Developers are in the best position to identify potential areas within systems that might lead to covert channels. Covert channel analysis is a meaningful activity when there is the potential for unauthorized information flows across security domains, such as in the case of systems that contain export-controlled information and have connections to external networks (i.e., networks that are not controlled by organizations). Covert channel analysis is also useful for multilevel secure systems, multiple security level systems, and cross-domain systems.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

sc-31_odp
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Covert Channel Analysis as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to secure architecture, boundary protection, communications protection, cryptography, and system isolation.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • network and trust-boundary diagrams
  • firewall and gateway configurations
  • cryptographic configuration and key records
  • segmentation and isolation test results

Common failure patterns

  • diagrams omit cloud and third-party paths
  • encryption enabled without key governance
  • flat trust zones allow unnecessary lateral movement
  • boundary rules accumulate without owner review

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. SC-31a.a covert channel analysis is performed to identify those aspects of communications within the system that are potential avenues for covert [Organization-defined: sc-31_odp] channels;
  2. SC-31b.the maximum bandwidth of those channels is estimated.

Examine

  • System and communications protection policy
  • procedures addressing covert channel analysis
  • system design documentation
  • system configuration settings and associated documentation
  • covert channel analysis documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel with covert channel analysis responsibilities
  • system developers/integrators

Test

  • Organizational process for conducting covert channel analysis
  • mechanisms supporting and/or implementing covert channel analysis
  • mechanisms supporting and/or implementing the capability to estimate the bandwidth of covert channels
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

SC-31(1) — Test Covert Channels for Exploitability

Test a subset of the identified covert channels to determine the channels that are exploitable.

Official discussion

None.

Assessment objectives and methods

a subset of the identified covert channels is tested to determine the channels that are exploitable.

Examine

  • System and communications protection policy
  • procedures addressing covert channel analysis
  • system design documentation
  • system configuration settings and associated documentation
  • list of covert channels
  • covert channel analysis documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel with covert channel analysis responsibilities

Test

  • Organizational process for testing covert channels
  • mechanisms supporting and/or implementing the testing of covert channel analysis
Official NIST control enhancement

SC-31(2) — Maximum Bandwidth

Reduce the maximum bandwidth for identified covert [Organization-defined: sc-31.02_odp.01] channels to [Organization-defined: values].

Official discussion

The complete elimination of covert channels, especially covert timing channels, is usually not possible without significant performance impacts.

Organization-defined parameters (2)
sc-31.02_odp.01
valuesvalues for the maximum bandwidth for identified covert channels are defined;
Assessment objectives and methods

the maximum bandwidth for identified covert [Organization-defined: sc-31.02_odp.01] channels is reduced to [Organization-defined: values].

Examine

  • System and communications protection policy
  • procedures addressing covert channel analysis
  • acquisition contracts for systems or services
  • acquisition documentation
  • system design documentation
  • system configuration settings and associated documentation
  • covert channel analysis documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel with covert channel analysis responsibilities
  • system developers/integrators

Test

  • Organizational process for conducting covert channel analysis
  • mechanisms supporting and/or implementing covert channel analysis
  • mechanisms supporting and/or implementing the capability to reduce the bandwidth of covert channels
Official NIST control enhancement

SC-31(3) — Measure Bandwidth in Operational Environments

Measure the bandwidth of [Organization-defined: subset of identified covert channels] in the operational environment of the system.

Official discussion

Measuring covert channel bandwidth in specified operational environments helps organizations determine how much information can be covertly leaked before such leakage adversely affects mission or business functions. Covert channel bandwidth may be significantly different when measured in settings that are independent of the specific environments of operation, including laboratories or system development environments.

Organization-defined parameters (1)
subset of identified covert channelssubset of identified covert channels whose bandwidth is to be measured in the operational environment of the system is defined;
Assessment objectives and methods

the bandwidth of [Organization-defined: subset of identified covert channels] is measured in the operational environment of the system.

Examine

  • System and communications protection policy
  • procedures addressing covert channel analysis
  • system design documentation
  • system configuration settings and associated documentation
  • covert channel analysis documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel with covert channel analysis responsibilities
  • system developers/integrators

Test

  • Organizational process for conducting covert channel analysis
  • mechanisms supporting and/or implementing covert channel analysis
  • mechanisms supporting and/or implementing the capability to measure the bandwidth of covert channels
Source record

Authoritative sources