Control statement
- a.Monitor and control communications at the external managed interfaces to the system and at key internal managed interfaces within the system;
- b.Implement subnetworks for publicly accessible system components that are [Organization-defined: sc-07_odp] separated from internal organizational networks; and
- c.Connect to external networks or systems only through managed interfaces consisting of boundary protection devices arranged in accordance with an organizational security and privacy architecture.
Discussion
Managed interfaces include gateways, routers, firewalls, guards, network-based malicious code analysis, virtualization systems, or encrypted tunnels implemented within a security architecture. Subnetworks that are physically or logically separated from internal networks are referred to as demilitarized zones or DMZs. Restricting or prohibiting interfaces within organizational systems includes restricting external web traffic to designated web servers within managed interfaces, prohibiting external traffic that appears to be spoofing internal addresses, and prohibiting internal traffic that appears to be spoofing external addresses. [SP 800-189](#f5edfe51-d1f2-422e-9b27-5d0e90b49c72) provides additional information on source address validation techniques to prevent ingress and egress of traffic with spoofed addresses. Commercial telecommunications services are provided by network components and consolidated management systems shared by customers. These services may also include third party-provided access lines and other service elements. Such services may represent sources of increased risk despite contract security provisions. Boundary protection may be implemented as a common control for all or part of an organizational network such that the boundary to be protected is greater than a system-specific boundary (i.e., an authorization boundary).
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use Boundary Protection as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to secure architecture, boundary protection, communications protection, cryptography, and system isolation.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- network and trust-boundary diagrams
- firewall and gateway configurations
- cryptographic configuration and key records
- segmentation and isolation test results
Common failure patterns
- diagrams omit cloud and third-party paths
- encryption enabled without key governance
- flat trust zones allow unnecessary lateral movement
- boundary rules accumulate without owner review
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- SC-07a.
- SC-07a.[01]communications at external managed interfaces to the system are monitored;
- SC-07a.[02]communications at external managed interfaces to the system are controlled;
- SC-07a.[03]communications at key internal managed interfaces within the system are monitored;
- SC-07a.[04]communications at key internal managed interfaces within the system are controlled;
- SC-07b.subnetworks for publicly accessible system components are [Organization-defined: sc-07_odp] separated from internal organizational networks;
- SC-07c.external networks or systems are only connected to through managed interfaces consisting of boundary protection devices arranged in accordance with an organizational security and privacy architecture.
Examine
- System and communications protection policy
- procedures addressing boundary protection
- list of key internal boundaries of the system
- system design documentation
- boundary protection hardware and software
- system configuration settings and associated documentation
- enterprise security architecture documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- system developer
- organizational personnel with boundary protection responsibilities
Test
- Mechanisms implementing boundary protection capabilities
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Related NIST SP 800-171 requirements
These Rev. 3 requirements cite this base control or one of its enhancements as a source. The relationship does not by itself determine contractual applicability or complete implementation.
Related NIST SP 800-172 requirements
These Rev. 3 requirements cite this base control or one of its enhancements as a source. The relationship does not by itself determine contractual applicability or complete implementation.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
SC-7(1) — Physically Separated Subnetworks
This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.
SC-7(2) — Public Access
This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.
SC-7(3) — Access Points
Limit the number of external network connections to the system.
Official discussion
Limiting the number of external network connections facilitates monitoring of inbound and outbound communications traffic. The Trusted Internet Connection [DHS TIC](#4f42ee6e-86cc-403b-a51f-76c2b4f81b54) initiative is an example of a federal guideline that requires limits on the number of external network connections. Limiting the number of external network connections to the system is important during transition periods from older to newer technologies (e.g., transitioning from IPv4 to IPv6 network protocols). Such transitions may require implementing the older and newer technologies simultaneously during the transition period and thus increase the number of access points to the system.
Assessment objectives and methods
the number of external network connections to the system is limited.
Examine
- System and communications protection policy
- procedures addressing boundary protection
- system design documentation
- boundary protection hardware and software
- system architecture and configuration documentation
- system configuration settings and associated documentation
- communications and network traffic monitoring logs
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- organizational personnel with boundary protection responsibilities
Test
- Mechanisms implementing boundary protection capabilities
- mechanisms limiting the number of external network connections to the system
SC-7(4) — External Telecommunications Services
- (a)Implement a managed interface for each external telecommunication service;
- (b)Establish a traffic flow policy for each managed interface;
- (c)Protect the confidentiality and integrity of the information being transmitted across each interface;
- (d)Document each exception to the traffic flow policy with a supporting mission or business need and duration of that need;
- (e)Review exceptions to the traffic flow policy [Organization-defined: frequency] and remove exceptions that are no longer supported by an explicit mission or business need;
- (f)Prevent unauthorized exchange of control plane traffic with external networks;
- (g)Publish information to enable remote networks to detect unauthorized control plane traffic from internal networks; and
- (h)Filter unauthorized control plane traffic from external networks.
Official discussion
External telecommunications services can provide data and/or voice communications services. Examples of control plane traffic include Border Gateway Protocol (BGP) routing, Domain Name System (DNS), and management protocols. See [SP 800-189](#f5edfe51-d1f2-422e-9b27-5d0e90b49c72) for additional information on the use of the resource public key infrastructure (RPKI) to protect BGP routes and detect unauthorized BGP announcements.
Organization-defined parameters (1)
Assessment objectives and methods
- SC-07(04)(a)a managed interface is implemented for each external telecommunication service;
- SC-07(04)(b)a traffic flow policy is established for each managed interface;
- SC-07(04)(c)
- SC-07(04)(c)[01]the confidentiality of the information being transmitted across each interface is protected;
- SC-07(04)(c)[02]the integrity of the information being transmitted across each interface is protected;
- SC-07(04)(d)each exception to the traffic flow policy is documented with a supporting mission or business need and duration of that need;
- SC-07(04)(e)
- SC-07(04)(e)[01]exceptions to the traffic flow policy are reviewed [Organization-defined: frequency];
- SC-07(04)(e)[02]exceptions to the traffic flow policy that are no longer supported by an explicit mission or business need are removed;
- SC-07(04)(f)unauthorized exchanges of control plan traffic with external networks are prevented;
- SC-07(04)(g)information is published to enable remote networks to detect unauthorized control plane traffic from internal networks;
- SC-07(04)(h)unauthorized control plane traffic is filtered from external networks.
Examine
- System and communications protection policy
- traffic flow policy
- information flow control policy
- procedures addressing boundary protection
- system security architecture
- system design documentation
- boundary protection hardware and software
- system architecture and configuration documentation
- system configuration settings and associated documentation
- records of traffic flow policy exceptions
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- organizational personnel with boundary protection responsibilities
Test
- Organizational processes for documenting and reviewing exceptions to the traffic flow policy
- organizational processes for removing exceptions to the traffic flow policy
- mechanisms implementing boundary protection capabilities
- managed interfaces implementing traffic flow policy
Related controls
SC-7(5) — Deny by Default — Allow by Exception
Deny network communications traffic by default and allow network communications traffic by exception [Organization-defined: sc-07.05_odp.01].
Official discussion
Denying by default and allowing by exception applies to inbound and outbound network communications traffic. A deny-all, permit-by-exception network communications traffic policy ensures that only those system connections that are essential and approved are allowed. Deny by default, allow by exception also applies to a system that is connected to an external system.
Organization-defined parameters (2)
Assessment objectives and methods
- SC-07(05)[01]network communications traffic is denied by default [Organization-defined: sc-07.05_odp.01];
- SC-07(05)[02]network communications traffic is allowed by exception [Organization-defined: sc-07.05_odp.01].
Examine
- System and communications protection policy
- procedures addressing boundary protection
- system design documentation
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- system developer
- organizational personnel with boundary protection responsibilities
Test
- Mechanisms implementing traffic management at managed interfaces
SC-7(6) — Response to Recognized Failures
This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.
SC-7(7) — Split Tunneling for Remote Devices
Prevent split tunneling for remote devices connecting to organizational systems unless the split tunnel is securely provisioned using [Organization-defined: safeguards].
Official discussion
Split tunneling is the process of allowing a remote user or device to establish a non-remote connection with a system and simultaneously communicate via some other connection to a resource in an external network. This method of network access enables a user to access remote devices and simultaneously, access uncontrolled networks. Split tunneling might be desirable by remote users to communicate with local system resources, such as printers or file servers. However, split tunneling can facilitate unauthorized external connections, making the system vulnerable to attack and to exfiltration of organizational information. Split tunneling can be prevented by disabling configuration settings that allow such capability in remote devices and by preventing those configuration settings from being configurable by users. Prevention can also be achieved by the detection of split tunneling (or of configuration settings that allow split tunneling) in the remote device, and by prohibiting the connection if the remote device is using split tunneling. A virtual private network (VPN) can be used to securely provision a split tunnel. A securely provisioned VPN includes locking connectivity to exclusive, managed, and named environments, or to a specific set of pre-approved addresses, without user control.
Organization-defined parameters (1)
Assessment objectives and methods
split tunneling is prevented for remote devices connecting to organizational systems unless the split tunnel is securely provisioned using [Organization-defined: safeguards].
Examine
- System and communications protection policy
- procedures addressing boundary protection
- system design documentation
- system hardware and software
- system architecture
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- system developer
- organizational personnel with boundary protection responsibilities
Test
- Mechanisms implementing boundary protection capabilities
- mechanisms supporting/restricting non-remote connections
SC-7(8) — Route Traffic to Authenticated Proxy Servers
Route [Organization-defined: internal communications traffic] to [Organization-defined: external networks] through authenticated proxy servers at managed interfaces.
Official discussion
External networks are networks outside of organizational control. A proxy server is a server (i.e., system or application) that acts as an intermediary for clients requesting system resources from non-organizational or other organizational servers. System resources that may be requested include files, connections, web pages, or services. Client requests established through a connection to a proxy server are assessed to manage complexity and provide additional protection by limiting direct connectivity. Web content filtering devices are one of the most common proxy servers that provide access to the Internet. Proxy servers can support the logging of Transmission Control Protocol sessions and the blocking of specific Uniform Resource Locators, Internet Protocol addresses, and domain names. Web proxies can be configured with organization-defined lists of authorized and unauthorized websites. Note that proxy servers may inhibit the use of virtual private networks (VPNs) and create the potential for "man-in-the-middle" attacks (depending on the implementation).
Organization-defined parameters (2)
Assessment objectives and methods
[Organization-defined: internal communications traffic] is routed to [Organization-defined: external networks] through authenticated proxy servers at managed interfaces.
Examine
- System and communications protection policy
- procedures addressing boundary protection
- system design documentation
- system hardware and software
- system architecture
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- system developer
- organizational personnel with boundary protection responsibilities
Test
- Mechanisms implementing traffic management through authenticated proxy servers at managed interfaces
Related controls
SC-7(9) — Restrict Threatening Outgoing Communications Traffic
- (a)Detect and deny outgoing communications traffic posing a threat to external systems; and
- (b)Audit the identity of internal users associated with denied communications.
Official discussion
Detecting outgoing communications traffic from internal actions that may pose threats to external systems is known as extrusion detection. Extrusion detection is carried out within the system at managed interfaces. Extrusion detection includes the analysis of incoming and outgoing communications traffic while searching for indications of internal threats to the security of external systems. Internal threats to external systems include traffic indicative of denial-of-service attacks, traffic with spoofed source addresses, and traffic that contains malicious code. Organizations have criteria to determine, update, and manage identified threats related to extrusion detection.
Assessment objectives and methods
- SC-07(09)(a)
- SC-07(09)(a)[01]outgoing communications traffic posing a threat to external systems is detected;
- SC-07(09)(a)[02]outgoing communications traffic posing a threat to external systems is denied;
- SC-07(09)(b)the identity of internal users associated with denied communications is audited.
Examine
- System and communications protection policy
- procedures addressing boundary protection
- system design documentation
- system hardware and software
- system architecture
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- system developer
- organizational personnel with boundary protection responsibilities
Test
- Mechanisms implementing boundary protection capabilities
- mechanisms implementing the detection and denial of threatening outgoing communications traffic
- mechanisms implementing auditing of outgoing communications traffic
Related controls
SC-7(10) — Prevent Exfiltration
- (a)Prevent the exfiltration of information; and
- (b)Conduct exfiltration tests [Organization-defined: frequency].
Official discussion
Prevention of exfiltration applies to both the intentional and unintentional exfiltration of information. Techniques used to prevent the exfiltration of information from systems may be implemented at internal endpoints, external boundaries, and across managed interfaces and include adherence to protocol formats, monitoring for beaconing activity from systems, disconnecting external network interfaces except when explicitly needed, employing traffic profile analysis to detect deviations from the volume and types of traffic expected, call backs to command and control centers, conducting penetration testing, monitoring for steganography, disassembling and reassembling packet headers, and using data loss and data leakage prevention tools. Devices that enforce strict adherence to protocol formats include deep packet inspection firewalls and Extensible Markup Language (XML) gateways. The devices verify adherence to protocol formats and specifications at the application layer and identify vulnerabilities that cannot be detected by devices that operate at the network or transport layers. The prevention of exfiltration is similar to data loss prevention or data leakage prevention and is closely associated with cross-domain solutions and system guards that enforce information flow requirements.
Organization-defined parameters (1)
Assessment objectives and methods
- SC-07(10)(a)the exfiltration of information is prevented;
- SC-07(10)(b)exfiltration tests are conducted [Organization-defined: frequency].
Examine
- System and communications protection policy
- procedures addressing boundary protection
- system design documentation
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- organizational personnel with boundary protection responsibilities
Test
- Mechanisms implementing boundary protection capabilities that prevent the unauthorized exfiltration of information across managed interfaces
Related controls
SC-7(11) — Restrict Incoming Communications Traffic
Only allow incoming communications from [Organization-defined: authorized sources] to be routed to [Organization-defined: authorized destinations].
Official discussion
General source address validation techniques are applied to restrict the use of illegal and unallocated source addresses as well as source addresses that should only be used within the system. The restriction of incoming communications traffic provides determinations that source and destination address pairs represent authorized or allowed communications. Determinations can be based on several factors, including the presence of such address pairs in the lists of authorized or allowed communications, the absence of such address pairs in lists of unauthorized or disallowed pairs, or meeting more general rules for authorized or allowed source and destination pairs. Strong authentication of network addresses is not possible without the use of explicit security protocols, and thus, addresses can often be spoofed. Further, identity-based incoming traffic restriction methods can be employed, including router access control lists and firewall rules.
Organization-defined parameters (2)
Assessment objectives and methods
only incoming communications from [Organization-defined: authorized sources] are allowed to be routed to [Organization-defined: authorized destinations].
Examine
- System and communications protection policy
- procedures addressing boundary protection
- system design documentation
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- system developer
- organizational personnel with boundary protection responsibilities
Test
- Mechanisms implementing boundary protection capabilities with respect to source/destination address pairs
Related controls
SC-7(12) — Host-based Protection
Implement [Organization-defined: host-based boundary protection mechanisms] at [Organization-defined: system components].
Official discussion
Host-based boundary protection mechanisms include host-based firewalls. System components that employ host-based boundary protection mechanisms include servers, workstations, notebook computers, and mobile devices.
Organization-defined parameters (2)
Assessment objectives and methods
[Organization-defined: host-based boundary protection mechanisms] are implemented at [Organization-defined: system components].
Examine
- System and communications protection policy
- procedures addressing boundary protection
- system design documentation
- boundary protection hardware and software
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- organizational personnel with boundary protection responsibilities
- system users
Test
- Mechanisms implementing host-based boundary protection capabilities
SC-7(13) — Isolation of Security Tools, Mechanisms, and Support Components
Isolate [Organization-defined: information security tools, mechanisms, and support components] from other internal system components by implementing physically separate subnetworks with managed interfaces to other components of the system.
Official discussion
Physically separate subnetworks with managed interfaces are useful in isolating computer network defenses from critical operational processing networks to prevent adversaries from discovering the analysis and forensics techniques employed by organizations.
Organization-defined parameters (1)
Assessment objectives and methods
[Organization-defined: information security tools, mechanisms, and support components] are isolated from other internal system components by implementing physically separate subnetworks with managed interfaces to other components of the system.
Examine
- System and communications protection policy
- procedures addressing boundary protection
- system design documentation
- system hardware and software
- system architecture
- system configuration settings and associated documentation
- list of security tools and support components to be isolated from other internal system components
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- organizational personnel with boundary protection responsibilities
Test
- Mechanisms supporting and/or implementing the isolation of information security tools, mechanisms, and support components
Related controls
SC-7(14) — Protect Against Unauthorized Physical Connections
Protect against unauthorized physical connections at [Organization-defined: managed interfaces].
Official discussion
Systems that operate at different security categories or classification levels may share common physical and environmental controls, since the systems may share space within the same facilities. In practice, it is possible that these separate systems may share common equipment rooms, wiring closets, and cable distribution paths. Protection against unauthorized physical connections can be achieved by using clearly identified and physically separated cable trays, connection frames, and patch panels for each side of managed interfaces with physical access controls that enforce limited authorized access to these items.
Organization-defined parameters (1)
Assessment objectives and methods
[Organization-defined: managed interfaces] are protected against unauthorized physical connections.
Examine
- System and communications protection policy
- procedures addressing boundary protection
- system design documentation
- system hardware and software
- system architecture
- system configuration settings and associated documentation
- facility communications and wiring diagram system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- organizational personnel with boundary protection responsibilities
Test
- Mechanisms supporting and/or implementing protection against unauthorized physical connections
Related controls
SC-7(15) — Networked Privileged Accesses
Route networked, privileged accesses through a dedicated, managed interface for purposes of access control and auditing.
Official discussion
Privileged access provides greater accessibility to system functions, including security functions. Adversaries attempt to gain privileged access to systems through remote access to cause adverse mission or business impacts, such as by exfiltrating information or bringing down a critical system capability. Routing networked, privileged access requests through a dedicated, managed interface further restricts privileged access for increased access control and auditing.
Assessment objectives and methods
- SC-07(15)[01]networked, privileged accesses are routed through a dedicated, managed interface for purposes of access control;
- SC-07(15)[02]networked, privileged accesses are routed through a dedicated, managed interface for purposes of auditing.
Examine
- System and communications protection policy
- procedures addressing boundary protection
- system design documentation
- system hardware and software
- system architecture
- system configuration settings and associated documentation
- audit logs
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- system developer
- organizational personnel with boundary protection responsibilities
Test
- Mechanisms supporting and/or implementing the routing of networked, privileged access through dedicated, managed interfaces
Related controls
SC-7(16) — Prevent Discovery of System Components
Prevent the discovery of specific system components that represent a managed interface.
Official discussion
Preventing the discovery of system components representing a managed interface helps protect network addresses of those components from discovery through common tools and techniques used to identify devices on networks. Network addresses are not available for discovery and require prior knowledge for access. Preventing the discovery of components and devices can be accomplished by not publishing network addresses, using network address translation, or not entering the addresses in domain name systems. Another prevention technique is to periodically change network addresses.
Assessment objectives and methods
the discovery of specific system components that represent a managed interface is prevented.
Examine
- System and communications protection policy
- procedures addressing boundary protection
- system design documentation
- system hardware and software
- system architecture
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- system developer
- organizational personnel with boundary protection responsibilities
Test
- Mechanisms supporting and/or implementing the prevention of discovery of system components at managed interfaces
SC-7(17) — Automated Enforcement of Protocol Formats
Enforce adherence to protocol formats.
Official discussion
System components that enforce protocol formats include deep packet inspection firewalls and XML gateways. The components verify adherence to protocol formats and specifications at the application layer and identify vulnerabilities that cannot be detected by devices operating at the network or transport layers.
Assessment objectives and methods
adherence to protocol formats is enforced.
Examine
- System and communications protection policy
- procedures addressing boundary protection
- system design documentation
- system architecture
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- system developer
- organizational personnel with boundary protection responsibilities
Test
- Mechanisms supporting and/or implementing the enforcement of adherence to protocol formats
Related controls
SC-7(18) — Fail Secure
Prevent systems from entering unsecure states in the event of an operational failure of a boundary protection device.
Official discussion
Fail secure is a condition achieved by employing mechanisms to ensure that in the event of operational failures of boundary protection devices at managed interfaces, systems do not enter into unsecure states where intended security properties no longer hold. Managed interfaces include routers, firewalls, and application gateways that reside on protected subnetworks (commonly referred to as demilitarized zones). Failures of boundary protection devices cannot lead to or cause information external to the devices to enter the devices nor can failures permit unauthorized information releases.
Assessment objectives and methods
systems are prevented from entering unsecure states in the event of an operational failure of a boundary protection device.
Examine
- System and communications protection policy
- procedures addressing boundary protection
- system design documentation
- system architecture
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- system developer
- organizational personnel with boundary protection responsibilities
Test
- Mechanisms supporting and/or implementing secure failure
Related controls
SC-7(19) — Block Communication from Non-organizationally Configured Hosts
Block inbound and outbound communications traffic between [Organization-defined: communication clients] that are independently configured by end users and external service providers.
Official discussion
Communication clients independently configured by end users and external service providers include instant messaging clients and video conferencing software and applications. Traffic blocking does not apply to communication clients that are configured by organizations to perform authorized functions.
Organization-defined parameters (1)
Assessment objectives and methods
- SC-07(19)[01]inbound communications traffic is blocked between [Organization-defined: communication clients] that are independently configured by end users and external service providers;
- SC-07(19)[02]outbound communications traffic is blocked between [Organization-defined: communication clients] that are independently configured by end users and external service providers.
Examine
- System and communications protection policy
- procedures addressing boundary protection
- system design documentation
- system hardware and software
- system architecture
- system configuration settings and associated documentation
- list of communication clients independently configured by end users and external service providers
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- organizational personnel with boundary protection responsibilities
Test
- Mechanisms supporting and/or implementing the blocking of inbound and outbound communications traffic between communication clients independently configured by end users and external service providers
SC-7(20) — Dynamic Isolation and Segregation
Provide the capability to dynamically isolate [Organization-defined: system components] from other system components.
Official discussion
The capability to dynamically isolate certain internal system components is useful when it is necessary to partition or separate system components of questionable origin from components that possess greater trustworthiness. Component isolation reduces the attack surface of organizational systems. Isolating selected system components can also limit the damage from successful attacks when such attacks occur.
Organization-defined parameters (1)
Assessment objectives and methods
the capability to dynamically isolate [Organization-defined: system components] from other system components is provided.
Examine
- System and communications protection policy
- procedures addressing boundary protection
- system design documentation
- system hardware and software
- system architecture
- system configuration settings and associated documentation
- list of system components to be dynamically isolated/segregated from other components of the system
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- system developer
- organizational personnel with boundary protection responsibilities
Test
- Mechanisms supporting and/or implementing the capability to dynamically isolate/segregate system components
SC-7(21) — Isolation of System Components
Employ boundary protection mechanisms to isolate [Organization-defined: system components] supporting [Organization-defined: missions and/or business functions].
Official discussion
Organizations can isolate system components that perform different mission or business functions. Such isolation limits unauthorized information flows among system components and provides the opportunity to deploy greater levels of protection for selected system components. Isolating system components with boundary protection mechanisms provides the capability for increased protection of individual system components and to more effectively control information flows between those components. Isolating system components provides enhanced protection that limits the potential harm from hostile cyber-attacks and errors. The degree of isolation varies depending upon the mechanisms chosen. Boundary protection mechanisms include routers, gateways, and firewalls that separate system components into physically separate networks or subnetworks; cross-domain devices that separate subnetworks; virtualization techniques; and the encryption of information flows among system components using distinct encryption keys.
Organization-defined parameters (2)
Assessment objectives and methods
boundary protection mechanisms are employed to isolate [Organization-defined: system components] supporting [Organization-defined: missions and/or business functions].
Examine
- System and communications protection policy
- procedures addressing boundary protection
- system design documentation
- system hardware and software
- enterprise architecture documentation
- system architecture
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- organizational personnel with boundary protection responsibilities
Test
- Mechanisms supporting and/or implementing the capability to separate system components supporting organizational missions and/or business functions
Related controls
SC-7(22) — Separate Subnets for Connecting to Different Security Domains
Implement separate network addresses to connect to systems in different security domains.
Official discussion
The decomposition of systems into subnetworks (i.e., subnets) helps to provide the appropriate level of protection for network connections to different security domains that contain information with different security categories or classification levels.
Assessment objectives and methods
separate network addresses are implemented to connect to systems in different security domains.
Examine
- System and communications protection policy
- procedures addressing boundary protection
- system design documentation
- system hardware and software
- system architecture
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- system developer
- organizational personnel with boundary protection responsibilities
Test
- Mechanisms supporting and/or implementing separate network addresses/different subnets
SC-7(23) — Disable Sender Feedback on Protocol Validation Failure
Disable feedback to senders on protocol format validation failure.
Official discussion
Disabling feedback to senders when there is a failure in protocol validation format prevents adversaries from obtaining information that would otherwise be unavailable.
Assessment objectives and methods
feedback to senders is disabled on protocol format validation failure.
Examine
- System and communications protection policy
- procedures addressing boundary protection
- system design documentation
- system hardware and software
- system architecture
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- system developer
- organizational personnel with boundary protection responsibilities
Test
- Mechanisms supporting and/or implementing the disabling of feedback to senders on protocol format validation failure
SC-7(24) — Personally Identifiable Information
For systems that process personally identifiable information:
- (a)Apply the following processing rules to data elements of personally identifiable information: [Organization-defined: processing rules];
- (b)Monitor for permitted processing at the external interfaces to the system and at key internal boundaries within the system;
- (c)Document each processing exception; and
- (d)Review and remove exceptions that are no longer supported.
Official discussion
Managing the processing of personally identifiable information is an important aspect of protecting an individual’s privacy. Applying, monitoring for, and documenting exceptions to processing rules ensure that personally identifiable information is processed only in accordance with established privacy requirements.
Organization-defined parameters (1)
Assessment objectives and methods
- SC-07(24)(a)[Organization-defined: processing rules] are applied to data elements of personally identifiable information on systems that process personally identifiable information;
- SC-07(24)(b)
- SC-07(24)(b)[01]permitted processing is monitored at the external interfaces to the systems that process personally identifiable information;
- SC-07(24)(b)[02]permitted processing is monitored at key internal boundaries within the systems that process personally identifiable information;
- SC-07(24)(c)each processing exception is documented for systems that process personally identifiable information;
- SC-07(24)(d)
- SC-07(24)(d)[01]exceptions for systems that process personally identifiable information are reviewed;
- SC-07(24)(d)[02]exceptions for systems that process personally identifiable information that are no longer supported are removed.
Examine
- System and communications protection policy
- procedures addressing boundary protection
- personally identifiable information processing policies
- list of key internal boundaries of the system
- system design documentation
- system configuration settings and associated documentation
- enterprise security and privacy architecture documentation
- system audit records
- system security plan
- privacy plan
- personally identifiable information inventory documentation
- data mapping documentation
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security and privacy responsibilities
- system developer
- organizational personnel with boundary protection responsibilities
Test
- Mechanisms implementing boundary protection capabilities
Related controls
SC-7(25) — Unclassified National Security System Connections
Prohibit the direct connection of [Organization-defined: unclassified national security system] to an external network without the use of [Organization-defined: boundary protection device].
Official discussion
A direct connection is a dedicated physical or virtual connection between two or more systems. Organizations typically do not have complete control over external networks, including the Internet. Boundary protection devices (e.g., firewalls, gateways, and routers) mediate communications and information flows between unclassified national security systems and external networks.
Organization-defined parameters (2)
Assessment objectives and methods
the direct connection of [Organization-defined: unclassified national security system] to an external network without the use of [Organization-defined: boundary protection device] is prohibited.
Examine
- System and communications protection policy
- procedures addressing boundary protection
- system design documentation
- system hardware and software
- system architecture
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- system developer
- organizational personnel with boundary protection responsibilities
Test
- Mechanisms prohibiting the direct connection of unclassified national security systems to an external network
SC-7(26) — Classified National Security System Connections
Prohibit the direct connection of a classified national security system to an external network without the use of [Organization-defined: boundary protection device].
Official discussion
A direct connection is a dedicated physical or virtual connection between two or more systems. Organizations typically do not have complete control over external networks, including the Internet. Boundary protection devices (e.g., firewalls, gateways, and routers) mediate communications and information flows between classified national security systems and external networks. In addition, approved boundary protection devices (typically managed interface or cross-domain systems) provide information flow enforcement from systems to external networks.
Organization-defined parameters (1)
Assessment objectives and methods
the direct connection of classified national security system to an external network without the use of a [Organization-defined: boundary protection device] is prohibited.
Examine
- System and communications protection policy
- procedures addressing boundary protection
- system design documentation
- system hardware and software
- system architecture
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- system developer
- organizational personnel with boundary protection responsibilities
Test
- Mechanisms prohibiting the direct connection of classified national security systems to an external network
SC-7(27) — Unclassified Non-national Security System Connections
Prohibit the direct connection of [Organization-defined: unclassified, non-national security system] to an external network without the use of [Organization-defined: boundary protection device].
Official discussion
A direct connection is a dedicated physical or virtual connection between two or more systems. Organizations typically do not have complete control over external networks, including the Internet. Boundary protection devices (e.g., firewalls, gateways, and routers) mediate communications and information flows between unclassified non-national security systems and external networks.
Organization-defined parameters (2)
Assessment objectives and methods
the direct connection of [Organization-defined: unclassified, non-national security system] to an external network without the use of a [Organization-defined: boundary protection device] is prohibited.
Examine
- System and communications protection policy
- procedures addressing boundary protection
- system design documentation
- system hardware and software
- system architecture
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- system developer
- organizational personnel with boundary protection responsibilities
Test
- Mechanisms prohibiting the direct connection of unclassified, non-national security systems to an external network
SC-7(28) — Connections to Public Networks
Prohibit the direct connection of [Organization-defined: system] to a public network.
Official discussion
A direct connection is a dedicated physical or virtual connection between two or more systems. A public network is a network accessible to the public, including the Internet and organizational extranets with public access.
Organization-defined parameters (1)
Assessment objectives and methods
the direct connection of the [Organization-defined: system] to a public network is prohibited.
Examine
- System and communications protection policy
- procedures addressing boundary protection
- system design documentation
- system hardware and software
- system architecture
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- system developer
- organizational personnel with boundary protection responsibilities
Test
- Mechanisms prohibiting the direct connection of systems to an external network
SC-7(29) — Separate Subnets to Isolate Functions
Implement [Organization-defined: sc-07.29_odp.01] separate subnetworks to isolate the following critical system components and functions: [Organization-defined: critical system components and functions].
Official discussion
Separating critical system components and functions from other noncritical system components and functions through separate subnetworks may be necessary to reduce susceptibility to a catastrophic or debilitating breach or compromise that results in system failure. For example, physically separating the command and control function from the in-flight entertainment function through separate subnetworks in a commercial aircraft provides an increased level of assurance in the trustworthiness of critical system functions.
Organization-defined parameters (2)
Assessment objectives and methods
subnetworks are separated [Organization-defined: sc-07.29_odp.01] to isolate [Organization-defined: critical system components and functions].
Examine
- System and communications protection policy
- procedures addressing boundary protection
- system design documentation
- system hardware and software
- system architecture
- system configuration settings and associated documentation
- criticality analysis
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- system developer
- organizational personnel with boundary protection responsibilities
Test
- Mechanisms separating critical system components and functions
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.