Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

SC-5 — Denial-of-service Protection

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

3Enhancements
3Parameters
3Baseline memberships
3Assessment methods

SC — System and Communications Protection · NIST SP 800-53 Release 5.2.0

LowModerateHigh
Official NIST control content

Control statement

  1. a.[Organization-defined: sc-05_odp.02] the effects of the following types of denial-of-service events: [Organization-defined: types of denial-of-service events] ; and
  2. b.Employ the following controls to achieve the denial-of-service objective: [Organization-defined: controls by type of denial-of-service event].
Official NIST discussion

Discussion

Denial-of-service events may occur due to a variety of internal and external causes, such as an attack by an adversary or a lack of planning to support organizational needs with respect to capacity and bandwidth. Such attacks can occur across a wide range of network protocols (e.g., IPv4, IPv6). A variety of technologies are available to limit or eliminate the origination and effects of denial-of-service events. For example, boundary protection devices can filter certain types of packets to protect system components on internal networks from being directly affected by or the source of denial-of-service attacks. Employing increased network capacity and bandwidth combined with service redundancy also reduces the susceptibility to denial-of-service events.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

types of denial-of-service eventstypes of denial-of-service events to be protected against or limited are defined;
sc-05_odp.02
controls by type of denial-of-service eventcontrols to achieve the denial-of-service objective by type of denial-of-service event are defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Denial-of-service Protection as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to secure architecture, boundary protection, communications protection, cryptography, and system isolation.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • network and trust-boundary diagrams
  • firewall and gateway configurations
  • cryptographic configuration and key records
  • segmentation and isolation test results

Common failure patterns

  • diagrams omit cloud and third-party paths
  • encryption enabled without key governance
  • flat trust zones allow unnecessary lateral movement
  • boundary rules accumulate without owner review

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. SC-05a.the effects of [Organization-defined: types of denial-of-service events] are [Organization-defined: sc-05_odp.02];
  2. SC-05b.[Organization-defined: controls by type of denial-of-service event] are employed to achieve the denial-of-service protection objective.

Examine

  • System and communications protection policy
  • procedures addressing denial-of-service protection
  • system design documentation
  • list of denial-of-service attacks requiring employment of security safeguards to protect against or limit effects of such attacks
  • list of security safeguards protecting against or limiting the effects of denial-of-service attacks
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel with incident response responsibilities
  • system developer

Test

  • Mechanisms protecting against or limiting the effects of denial-of-service attacks
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

SC-5(1) — Restrict Ability to Attack Other Systems

Restrict the ability of individuals to launch the following denial-of-service attacks against other systems: [Organization-defined: denial-of-service attacks].

Official discussion

Restricting the ability of individuals to launch denial-of-service attacks requires the mechanisms commonly used for such attacks to be unavailable. Individuals of concern include hostile insiders or external adversaries who have breached or compromised the system and are using it to launch a denial-of-service attack. Organizations can restrict the ability of individuals to connect and transmit arbitrary information on the transport medium (i.e., wired networks, wireless networks, spoofed Internet protocol packets). Organizations can also limit the ability of individuals to use excessive system resources. Protection against individuals having the ability to launch denial-of-service attacks may be implemented on specific systems or boundary devices that prohibit egress to potential target systems.

Organization-defined parameters (1)
denial-of-service attacksdenial-of-service attacks for which to restrict the ability of individuals to launch are defined;
Assessment objectives and methods

the ability of individuals to launch [Organization-defined: denial-of-service attacks] against other systems is restricted.

Examine

  • System and communications protection policy
  • procedures addressing denial-of-service protection
  • system design documentation
  • list of denial-of-service attacks launched by individuals against systems
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel with incident response responsibilities
  • system developer

Test

  • Mechanisms restricting the ability to launch denial-of-service attacks against other systems
Official NIST control enhancement

SC-5(2) — Capacity, Bandwidth, and Redundancy

Manage capacity, bandwidth, or other redundancy to limit the effects of information flooding denial-of-service attacks.

Official discussion

Managing capacity ensures that sufficient capacity is available to counter flooding attacks. Managing capacity includes establishing selected usage priorities, quotas, partitioning, or load balancing.

Assessment objectives and methods

capacity, bandwidth, or other redundancies to limit the effects of information flooding denial-of-service attacks are managed.

Examine

  • System and communications protection policy
  • procedures addressing denial-of-service protection
  • system design documentation
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel with incident response responsibilities
  • system developer

Test

  • Mechanisms implementing the management of system bandwidth, capacity, and redundancy to limit the effects of information flooding denial-of-service attacks
Official NIST control enhancement

SC-5(3) — Detection and Monitoring

  1. (a)Employ the following monitoring tools to detect indicators of denial-of-service attacks against, or launched from, the system: [Organization-defined: monitoring tools] ; and
  2. (b)Monitor the following system resources to determine if sufficient resources exist to prevent effective denial-of-service attacks: [Organization-defined: system resources].
Official discussion

Organizations consider the utilization and capacity of system resources when managing risk associated with a denial of service due to malicious attacks. Denial-of-service attacks can originate from external or internal sources. System resources that are sensitive to denial of service include physical disk storage, memory, and CPU cycles. Techniques used to prevent denial-of-service attacks related to storage utilization and capacity include instituting disk quotas, configuring systems to automatically alert administrators when specific storage capacity thresholds are reached, using file compression technologies to maximize available storage space, and imposing separate partitions for system and user data.

Organization-defined parameters (2)
monitoring toolsmonitoring tools for detecting indicators of denial-of-service attacks are defined;
system resourcessystem resources to be monitored to determine if sufficient resources exist to prevent effective denial-of-service attacks are defined;
Assessment objectives and methods
  1. SC-05(03)(a)[Organization-defined: monitoring tools] are employed to detect indicators of denial-of-service attacks against or launched from the system;
  2. SC-05(03)(b)[Organization-defined: system resources] are monitored to determine if sufficient resources exist to prevent effective denial-of-service attacks.

Examine

  • System and communications protection policy
  • procedures addressing denial-of-service protection
  • system design documentation
  • system monitoring tools and techniques documentation
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel with detection and monitoring responsibilities

Test

  • Mechanisms/tools implementing system monitoring for denial-of-service attacks
Related controls
Source record

Authoritative sources