Control statement
- a.[Organization-defined: sc-05_odp.02] the effects of the following types of denial-of-service events: [Organization-defined: types of denial-of-service events] ; and
- b.Employ the following controls to achieve the denial-of-service objective: [Organization-defined: controls by type of denial-of-service event].
Discussion
Denial-of-service events may occur due to a variety of internal and external causes, such as an attack by an adversary or a lack of planning to support organizational needs with respect to capacity and bandwidth. Such attacks can occur across a wide range of network protocols (e.g., IPv4, IPv6). A variety of technologies are available to limit or eliminate the origination and effects of denial-of-service events. For example, boundary protection devices can filter certain types of packets to protect system components on internal networks from being directly affected by or the source of denial-of-service attacks. Employing increased network capacity and bandwidth combined with service redundancy also reduces the susceptibility to denial-of-service events.
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use Denial-of-service Protection as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to secure architecture, boundary protection, communications protection, cryptography, and system isolation.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- network and trust-boundary diagrams
- firewall and gateway configurations
- cryptographic configuration and key records
- segmentation and isolation test results
Common failure patterns
- diagrams omit cloud and third-party paths
- encryption enabled without key governance
- flat trust zones allow unnecessary lateral movement
- boundary rules accumulate without owner review
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- SC-05a.the effects of [Organization-defined: types of denial-of-service events] are [Organization-defined: sc-05_odp.02];
- SC-05b.[Organization-defined: controls by type of denial-of-service event] are employed to achieve the denial-of-service protection objective.
Examine
- System and communications protection policy
- procedures addressing denial-of-service protection
- system design documentation
- list of denial-of-service attacks requiring employment of security safeguards to protect against or limit effects of such attacks
- list of security safeguards protecting against or limiting the effects of denial-of-service attacks
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- organizational personnel with incident response responsibilities
- system developer
Test
- Mechanisms protecting against or limiting the effects of denial-of-service attacks
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
SC-5(1) — Restrict Ability to Attack Other Systems
Restrict the ability of individuals to launch the following denial-of-service attacks against other systems: [Organization-defined: denial-of-service attacks].
Official discussion
Restricting the ability of individuals to launch denial-of-service attacks requires the mechanisms commonly used for such attacks to be unavailable. Individuals of concern include hostile insiders or external adversaries who have breached or compromised the system and are using it to launch a denial-of-service attack. Organizations can restrict the ability of individuals to connect and transmit arbitrary information on the transport medium (i.e., wired networks, wireless networks, spoofed Internet protocol packets). Organizations can also limit the ability of individuals to use excessive system resources. Protection against individuals having the ability to launch denial-of-service attacks may be implemented on specific systems or boundary devices that prohibit egress to potential target systems.
Organization-defined parameters (1)
Assessment objectives and methods
the ability of individuals to launch [Organization-defined: denial-of-service attacks] against other systems is restricted.
Examine
- System and communications protection policy
- procedures addressing denial-of-service protection
- system design documentation
- list of denial-of-service attacks launched by individuals against systems
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- organizational personnel with incident response responsibilities
- system developer
Test
- Mechanisms restricting the ability to launch denial-of-service attacks against other systems
SC-5(2) — Capacity, Bandwidth, and Redundancy
Manage capacity, bandwidth, or other redundancy to limit the effects of information flooding denial-of-service attacks.
Official discussion
Managing capacity ensures that sufficient capacity is available to counter flooding attacks. Managing capacity includes establishing selected usage priorities, quotas, partitioning, or load balancing.
Assessment objectives and methods
capacity, bandwidth, or other redundancies to limit the effects of information flooding denial-of-service attacks are managed.
Examine
- System and communications protection policy
- procedures addressing denial-of-service protection
- system design documentation
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- organizational personnel with incident response responsibilities
- system developer
Test
- Mechanisms implementing the management of system bandwidth, capacity, and redundancy to limit the effects of information flooding denial-of-service attacks
SC-5(3) — Detection and Monitoring
- (a)Employ the following monitoring tools to detect indicators of denial-of-service attacks against, or launched from, the system: [Organization-defined: monitoring tools] ; and
- (b)Monitor the following system resources to determine if sufficient resources exist to prevent effective denial-of-service attacks: [Organization-defined: system resources].
Official discussion
Organizations consider the utilization and capacity of system resources when managing risk associated with a denial of service due to malicious attacks. Denial-of-service attacks can originate from external or internal sources. System resources that are sensitive to denial of service include physical disk storage, memory, and CPU cycles. Techniques used to prevent denial-of-service attacks related to storage utilization and capacity include instituting disk quotas, configuring systems to automatically alert administrators when specific storage capacity thresholds are reached, using file compression technologies to maximize available storage space, and imposing separate partitions for system and user data.
Organization-defined parameters (2)
Assessment objectives and methods
- SC-05(03)(a)[Organization-defined: monitoring tools] are employed to detect indicators of denial-of-service attacks against or launched from the system;
- SC-05(03)(b)[Organization-defined: system resources] are monitored to determine if sufficient resources exist to prevent effective denial-of-service attacks.
Examine
- System and communications protection policy
- procedures addressing denial-of-service protection
- system design documentation
- system monitoring tools and techniques documentation
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- organizational personnel with detection and monitoring responsibilities
Test
- Mechanisms/tools implementing system monitoring for denial-of-service attacks
Related controls
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.