Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, and individual lessons.

NIST SP 800-53 Learning Center

SC-7 — Boundary Protection

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

29Enhancements
1Parameters
3Baseline memberships
3Assessment methods

SC — System and Communications Protection · NIST SP 800-53 Release 5.2.0

LowModerateHigh
Official NIST control content

Control statement

  1. a.Monitor and control communications at the external managed interfaces to the system and at key internal managed interfaces within the system;
  2. b.Implement subnetworks for publicly accessible system components that are [Organization-defined: sc-07_odp] separated from internal organizational networks; and
  3. c.Connect to external networks or systems only through managed interfaces consisting of boundary protection devices arranged in accordance with an organizational security and privacy architecture.
Official NIST discussion

Discussion

Managed interfaces include gateways, routers, firewalls, guards, network-based malicious code analysis, virtualization systems, or encrypted tunnels implemented within a security architecture. Subnetworks that are physically or logically separated from internal networks are referred to as demilitarized zones or DMZs. Restricting or prohibiting interfaces within organizational systems includes restricting external web traffic to designated web servers within managed interfaces, prohibiting external traffic that appears to be spoofing internal addresses, and prohibiting internal traffic that appears to be spoofing external addresses. [SP 800-189](#f5edfe51-d1f2-422e-9b27-5d0e90b49c72) provides additional information on source address validation techniques to prevent ingress and egress of traffic with spoofed addresses. Commercial telecommunications services are provided by network components and consolidated management systems shared by customers. These services may also include third party-provided access lines and other service elements. Such services may represent sources of increased risk despite contract security provisions. Boundary protection may be implemented as a common control for all or part of an organizational network such that the boundary to be protected is greater than a system-specific boundary (i.e., an authorization boundary).

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

sc-07_odp
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Boundary Protection as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to secure architecture, boundary protection, communications protection, cryptography, and system isolation.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • network and trust-boundary diagrams
  • firewall and gateway configurations
  • cryptographic configuration and key records
  • segmentation and isolation test results

Common failure patterns

  • diagrams omit cloud and third-party paths
  • encryption enabled without key governance
  • flat trust zones allow unnecessary lateral movement
  • boundary rules accumulate without owner review

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. SC-07a.
    1. SC-07a.[01]communications at external managed interfaces to the system are monitored;
    2. SC-07a.[02]communications at external managed interfaces to the system are controlled;
    3. SC-07a.[03]communications at key internal managed interfaces within the system are monitored;
    4. SC-07a.[04]communications at key internal managed interfaces within the system are controlled;
  2. SC-07b.subnetworks for publicly accessible system components are [Organization-defined: sc-07_odp] separated from internal organizational networks;
  3. SC-07c.external networks or systems are only connected to through managed interfaces consisting of boundary protection devices arranged in accordance with an organizational security and privacy architecture.

Examine

  • System and communications protection policy
  • procedures addressing boundary protection
  • list of key internal boundaries of the system
  • system design documentation
  • boundary protection hardware and software
  • system configuration settings and associated documentation
  • enterprise security architecture documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • system developer
  • organizational personnel with boundary protection responsibilities

Test

  • Mechanisms implementing boundary protection capabilities
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official CUI requirement crosswalk

Related NIST SP 800-171 requirements

These Rev. 3 requirements cite this base control or one of its enhancements as a source. The relationship does not by itself determine contractual applicability or complete implementation.

Official CUI requirement crosswalk

Related NIST SP 800-172 requirements

These Rev. 3 requirements cite this base control or one of its enhancements as a source. The relationship does not by itself determine contractual applicability or complete implementation.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

SC-7(1) — Physically Separated Subnetworks

Withdrawn

This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.

Official NIST control enhancement

SC-7(2) — Public Access

Withdrawn

This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.

Official NIST control enhancement

SC-7(3) — Access Points

ModerateHigh

Limit the number of external network connections to the system.

Official discussion

Limiting the number of external network connections facilitates monitoring of inbound and outbound communications traffic. The Trusted Internet Connection [DHS TIC](#4f42ee6e-86cc-403b-a51f-76c2b4f81b54) initiative is an example of a federal guideline that requires limits on the number of external network connections. Limiting the number of external network connections to the system is important during transition periods from older to newer technologies (e.g., transitioning from IPv4 to IPv6 network protocols). Such transitions may require implementing the older and newer technologies simultaneously during the transition period and thus increase the number of access points to the system.

Assessment objectives and methods

the number of external network connections to the system is limited.

Examine

  • System and communications protection policy
  • procedures addressing boundary protection
  • system design documentation
  • boundary protection hardware and software
  • system architecture and configuration documentation
  • system configuration settings and associated documentation
  • communications and network traffic monitoring logs
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel with boundary protection responsibilities

Test

  • Mechanisms implementing boundary protection capabilities
  • mechanisms limiting the number of external network connections to the system
Official NIST control enhancement

SC-7(4) — External Telecommunications Services

ModerateHigh
  1. (a)Implement a managed interface for each external telecommunication service;
  2. (b)Establish a traffic flow policy for each managed interface;
  3. (c)Protect the confidentiality and integrity of the information being transmitted across each interface;
  4. (d)Document each exception to the traffic flow policy with a supporting mission or business need and duration of that need;
  5. (e)Review exceptions to the traffic flow policy [Organization-defined: frequency] and remove exceptions that are no longer supported by an explicit mission or business need;
  6. (f)Prevent unauthorized exchange of control plane traffic with external networks;
  7. (g)Publish information to enable remote networks to detect unauthorized control plane traffic from internal networks; and
  8. (h)Filter unauthorized control plane traffic from external networks.
Official discussion

External telecommunications services can provide data and/or voice communications services. Examples of control plane traffic include Border Gateway Protocol (BGP) routing, Domain Name System (DNS), and management protocols. See [SP 800-189](#f5edfe51-d1f2-422e-9b27-5d0e90b49c72) for additional information on the use of the resource public key infrastructure (RPKI) to protect BGP routes and detect unauthorized BGP announcements.

Organization-defined parameters (1)
frequencythe frequency at which to review exceptions to traffic flow policy is defined;
Assessment objectives and methods
  1. SC-07(04)(a)a managed interface is implemented for each external telecommunication service;
  2. SC-07(04)(b)a traffic flow policy is established for each managed interface;
  3. SC-07(04)(c)
    1. SC-07(04)(c)[01]the confidentiality of the information being transmitted across each interface is protected;
    2. SC-07(04)(c)[02]the integrity of the information being transmitted across each interface is protected;
  4. SC-07(04)(d)each exception to the traffic flow policy is documented with a supporting mission or business need and duration of that need;
  5. SC-07(04)(e)
    1. SC-07(04)(e)[01]exceptions to the traffic flow policy are reviewed [Organization-defined: frequency];
    2. SC-07(04)(e)[02]exceptions to the traffic flow policy that are no longer supported by an explicit mission or business need are removed;
  6. SC-07(04)(f)unauthorized exchanges of control plan traffic with external networks are prevented;
  7. SC-07(04)(g)information is published to enable remote networks to detect unauthorized control plane traffic from internal networks;
  8. SC-07(04)(h)unauthorized control plane traffic is filtered from external networks.

Examine

  • System and communications protection policy
  • traffic flow policy
  • information flow control policy
  • procedures addressing boundary protection
  • system security architecture
  • system design documentation
  • boundary protection hardware and software
  • system architecture and configuration documentation
  • system configuration settings and associated documentation
  • records of traffic flow policy exceptions
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel with boundary protection responsibilities

Test

  • Organizational processes for documenting and reviewing exceptions to the traffic flow policy
  • organizational processes for removing exceptions to the traffic flow policy
  • mechanisms implementing boundary protection capabilities
  • managed interfaces implementing traffic flow policy
Related controls
Official NIST control enhancement

SC-7(5) — Deny by Default — Allow by Exception

ModerateHigh

Deny network communications traffic by default and allow network communications traffic by exception [Organization-defined: sc-07.05_odp.01].

Official discussion

Denying by default and allowing by exception applies to inbound and outbound network communications traffic. A deny-all, permit-by-exception network communications traffic policy ensures that only those system connections that are essential and approved are allowed. Deny by default, allow by exception also applies to a system that is connected to an external system.

Organization-defined parameters (2)
sc-07.05_odp.01
systemssystems for which network communications traffic is denied by default and network communications traffic is allowed by exception are defined (if selected).
Assessment objectives and methods
  1. SC-07(05)[01]network communications traffic is denied by default [Organization-defined: sc-07.05_odp.01];
  2. SC-07(05)[02]network communications traffic is allowed by exception [Organization-defined: sc-07.05_odp.01].

Examine

  • System and communications protection policy
  • procedures addressing boundary protection
  • system design documentation
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • system developer
  • organizational personnel with boundary protection responsibilities

Test

  • Mechanisms implementing traffic management at managed interfaces
Official NIST control enhancement

SC-7(6) — Response to Recognized Failures

Withdrawn

This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.

Official NIST control enhancement

SC-7(7) — Split Tunneling for Remote Devices

ModerateHigh

Prevent split tunneling for remote devices connecting to organizational systems unless the split tunnel is securely provisioned using [Organization-defined: safeguards].

Official discussion

Split tunneling is the process of allowing a remote user or device to establish a non-remote connection with a system and simultaneously communicate via some other connection to a resource in an external network. This method of network access enables a user to access remote devices and simultaneously, access uncontrolled networks. Split tunneling might be desirable by remote users to communicate with local system resources, such as printers or file servers. However, split tunneling can facilitate unauthorized external connections, making the system vulnerable to attack and to exfiltration of organizational information. Split tunneling can be prevented by disabling configuration settings that allow such capability in remote devices and by preventing those configuration settings from being configurable by users. Prevention can also be achieved by the detection of split tunneling (or of configuration settings that allow split tunneling) in the remote device, and by prohibiting the connection if the remote device is using split tunneling. A virtual private network (VPN) can be used to securely provision a split tunnel. A securely provisioned VPN includes locking connectivity to exclusive, managed, and named environments, or to a specific set of pre-approved addresses, without user control.

Organization-defined parameters (1)
safeguardssafeguards to securely provision split tunneling are defined;
Assessment objectives and methods

split tunneling is prevented for remote devices connecting to organizational systems unless the split tunnel is securely provisioned using [Organization-defined: safeguards].

Examine

  • System and communications protection policy
  • procedures addressing boundary protection
  • system design documentation
  • system hardware and software
  • system architecture
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • system developer
  • organizational personnel with boundary protection responsibilities

Test

  • Mechanisms implementing boundary protection capabilities
  • mechanisms supporting/restricting non-remote connections
Official NIST control enhancement

SC-7(8) — Route Traffic to Authenticated Proxy Servers

ModerateHigh

Route [Organization-defined: internal communications traffic] to [Organization-defined: external networks] through authenticated proxy servers at managed interfaces.

Official discussion

External networks are networks outside of organizational control. A proxy server is a server (i.e., system or application) that acts as an intermediary for clients requesting system resources from non-organizational or other organizational servers. System resources that may be requested include files, connections, web pages, or services. Client requests established through a connection to a proxy server are assessed to manage complexity and provide additional protection by limiting direct connectivity. Web content filtering devices are one of the most common proxy servers that provide access to the Internet. Proxy servers can support the logging of Transmission Control Protocol sessions and the blocking of specific Uniform Resource Locators, Internet Protocol addresses, and domain names. Web proxies can be configured with organization-defined lists of authorized and unauthorized websites. Note that proxy servers may inhibit the use of virtual private networks (VPNs) and create the potential for "man-in-the-middle" attacks (depending on the implementation).

Organization-defined parameters (2)
internal communications trafficinternal communications traffic to be routed to external networks is defined;
external networksexternal networks to which internal communications traffic is to be routed are defined;
Assessment objectives and methods

[Organization-defined: internal communications traffic] is routed to [Organization-defined: external networks] through authenticated proxy servers at managed interfaces.

Examine

  • System and communications protection policy
  • procedures addressing boundary protection
  • system design documentation
  • system hardware and software
  • system architecture
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • system developer
  • organizational personnel with boundary protection responsibilities

Test

  • Mechanisms implementing traffic management through authenticated proxy servers at managed interfaces
Related controls
Official NIST control enhancement

SC-7(9) — Restrict Threatening Outgoing Communications Traffic

  1. (a)Detect and deny outgoing communications traffic posing a threat to external systems; and
  2. (b)Audit the identity of internal users associated with denied communications.
Official discussion

Detecting outgoing communications traffic from internal actions that may pose threats to external systems is known as extrusion detection. Extrusion detection is carried out within the system at managed interfaces. Extrusion detection includes the analysis of incoming and outgoing communications traffic while searching for indications of internal threats to the security of external systems. Internal threats to external systems include traffic indicative of denial-of-service attacks, traffic with spoofed source addresses, and traffic that contains malicious code. Organizations have criteria to determine, update, and manage identified threats related to extrusion detection.

Assessment objectives and methods
  1. SC-07(09)(a)
    1. SC-07(09)(a)[01]outgoing communications traffic posing a threat to external systems is detected;
    2. SC-07(09)(a)[02]outgoing communications traffic posing a threat to external systems is denied;
  2. SC-07(09)(b)the identity of internal users associated with denied communications is audited.

Examine

  • System and communications protection policy
  • procedures addressing boundary protection
  • system design documentation
  • system hardware and software
  • system architecture
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • system developer
  • organizational personnel with boundary protection responsibilities

Test

  • Mechanisms implementing boundary protection capabilities
  • mechanisms implementing the detection and denial of threatening outgoing communications traffic
  • mechanisms implementing auditing of outgoing communications traffic
Related controls
Official NIST control enhancement

SC-7(10) — Prevent Exfiltration

  1. (a)Prevent the exfiltration of information; and
  2. (b)Conduct exfiltration tests [Organization-defined: frequency].
Official discussion

Prevention of exfiltration applies to both the intentional and unintentional exfiltration of information. Techniques used to prevent the exfiltration of information from systems may be implemented at internal endpoints, external boundaries, and across managed interfaces and include adherence to protocol formats, monitoring for beaconing activity from systems, disconnecting external network interfaces except when explicitly needed, employing traffic profile analysis to detect deviations from the volume and types of traffic expected, call backs to command and control centers, conducting penetration testing, monitoring for steganography, disassembling and reassembling packet headers, and using data loss and data leakage prevention tools. Devices that enforce strict adherence to protocol formats include deep packet inspection firewalls and Extensible Markup Language (XML) gateways. The devices verify adherence to protocol formats and specifications at the application layer and identify vulnerabilities that cannot be detected by devices that operate at the network or transport layers. The prevention of exfiltration is similar to data loss prevention or data leakage prevention and is closely associated with cross-domain solutions and system guards that enforce information flow requirements.

Organization-defined parameters (1)
frequencythe frequency for conducting exfiltration tests is defined;
Assessment objectives and methods
  1. SC-07(10)(a)the exfiltration of information is prevented;
  2. SC-07(10)(b)exfiltration tests are conducted [Organization-defined: frequency].

Examine

  • System and communications protection policy
  • procedures addressing boundary protection
  • system design documentation
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel with boundary protection responsibilities

Test

  • Mechanisms implementing boundary protection capabilities that prevent the unauthorized exfiltration of information across managed interfaces
Related controls
Official NIST control enhancement

SC-7(11) — Restrict Incoming Communications Traffic

Only allow incoming communications from [Organization-defined: authorized sources] to be routed to [Organization-defined: authorized destinations].

Official discussion

General source address validation techniques are applied to restrict the use of illegal and unallocated source addresses as well as source addresses that should only be used within the system. The restriction of incoming communications traffic provides determinations that source and destination address pairs represent authorized or allowed communications. Determinations can be based on several factors, including the presence of such address pairs in the lists of authorized or allowed communications, the absence of such address pairs in lists of unauthorized or disallowed pairs, or meeting more general rules for authorized or allowed source and destination pairs. Strong authentication of network addresses is not possible without the use of explicit security protocols, and thus, addresses can often be spoofed. Further, identity-based incoming traffic restriction methods can be employed, including router access control lists and firewall rules.

Organization-defined parameters (2)
authorized sourcesauthorized sources of incoming communications to be routed are defined;
authorized destinationsauthorized destinations to which incoming communications from authorized sources may be routed are defined;
Assessment objectives and methods

only incoming communications from [Organization-defined: authorized sources] are allowed to be routed to [Organization-defined: authorized destinations].

Examine

  • System and communications protection policy
  • procedures addressing boundary protection
  • system design documentation
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • system developer
  • organizational personnel with boundary protection responsibilities

Test

  • Mechanisms implementing boundary protection capabilities with respect to source/destination address pairs
Related controls
Official NIST control enhancement

SC-7(12) — Host-based Protection

Implement [Organization-defined: host-based boundary protection mechanisms] at [Organization-defined: system components].

Official discussion

Host-based boundary protection mechanisms include host-based firewalls. System components that employ host-based boundary protection mechanisms include servers, workstations, notebook computers, and mobile devices.

Organization-defined parameters (2)
host-based boundary protection mechanismshost-based boundary protection mechanisms to be implemented are defined;
system componentssystem components where host-based boundary protection mechanisms are to be implemented are defined;
Assessment objectives and methods

[Organization-defined: host-based boundary protection mechanisms] are implemented at [Organization-defined: system components].

Examine

  • System and communications protection policy
  • procedures addressing boundary protection
  • system design documentation
  • boundary protection hardware and software
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel with boundary protection responsibilities
  • system users

Test

  • Mechanisms implementing host-based boundary protection capabilities
Official NIST control enhancement

SC-7(13) — Isolation of Security Tools, Mechanisms, and Support Components

Isolate [Organization-defined: information security tools, mechanisms, and support components] from other internal system components by implementing physically separate subnetworks with managed interfaces to other components of the system.

Official discussion

Physically separate subnetworks with managed interfaces are useful in isolating computer network defenses from critical operational processing networks to prevent adversaries from discovering the analysis and forensics techniques employed by organizations.

Organization-defined parameters (1)
information security tools, mechanisms, and support componentsinformation security tools, mechanisms, and support components to be isolated from other internal system components are defined;
Assessment objectives and methods

[Organization-defined: information security tools, mechanisms, and support components] are isolated from other internal system components by implementing physically separate subnetworks with managed interfaces to other components of the system.

Examine

  • System and communications protection policy
  • procedures addressing boundary protection
  • system design documentation
  • system hardware and software
  • system architecture
  • system configuration settings and associated documentation
  • list of security tools and support components to be isolated from other internal system components
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel with boundary protection responsibilities

Test

  • Mechanisms supporting and/or implementing the isolation of information security tools, mechanisms, and support components
Related controls
Official NIST control enhancement

SC-7(14) — Protect Against Unauthorized Physical Connections

Protect against unauthorized physical connections at [Organization-defined: managed interfaces].

Official discussion

Systems that operate at different security categories or classification levels may share common physical and environmental controls, since the systems may share space within the same facilities. In practice, it is possible that these separate systems may share common equipment rooms, wiring closets, and cable distribution paths. Protection against unauthorized physical connections can be achieved by using clearly identified and physically separated cable trays, connection frames, and patch panels for each side of managed interfaces with physical access controls that enforce limited authorized access to these items.

Organization-defined parameters (1)
managed interfacesmanaged interfaces to be protected against unauthorized physical connections are defined;
Assessment objectives and methods

[Organization-defined: managed interfaces] are protected against unauthorized physical connections.

Examine

  • System and communications protection policy
  • procedures addressing boundary protection
  • system design documentation
  • system hardware and software
  • system architecture
  • system configuration settings and associated documentation
  • facility communications and wiring diagram system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel with boundary protection responsibilities

Test

  • Mechanisms supporting and/or implementing protection against unauthorized physical connections
Related controls
Official NIST control enhancement

SC-7(15) — Networked Privileged Accesses

Route networked, privileged accesses through a dedicated, managed interface for purposes of access control and auditing.

Official discussion

Privileged access provides greater accessibility to system functions, including security functions. Adversaries attempt to gain privileged access to systems through remote access to cause adverse mission or business impacts, such as by exfiltrating information or bringing down a critical system capability. Routing networked, privileged access requests through a dedicated, managed interface further restricts privileged access for increased access control and auditing.

Assessment objectives and methods
  1. SC-07(15)[01]networked, privileged accesses are routed through a dedicated, managed interface for purposes of access control;
  2. SC-07(15)[02]networked, privileged accesses are routed through a dedicated, managed interface for purposes of auditing.

Examine

  • System and communications protection policy
  • procedures addressing boundary protection
  • system design documentation
  • system hardware and software
  • system architecture
  • system configuration settings and associated documentation
  • audit logs
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • system developer
  • organizational personnel with boundary protection responsibilities

Test

  • Mechanisms supporting and/or implementing the routing of networked, privileged access through dedicated, managed interfaces
Related controls
Official NIST control enhancement

SC-7(16) — Prevent Discovery of System Components

Prevent the discovery of specific system components that represent a managed interface.

Official discussion

Preventing the discovery of system components representing a managed interface helps protect network addresses of those components from discovery through common tools and techniques used to identify devices on networks. Network addresses are not available for discovery and require prior knowledge for access. Preventing the discovery of components and devices can be accomplished by not publishing network addresses, using network address translation, or not entering the addresses in domain name systems. Another prevention technique is to periodically change network addresses.

Assessment objectives and methods

the discovery of specific system components that represent a managed interface is prevented.

Examine

  • System and communications protection policy
  • procedures addressing boundary protection
  • system design documentation
  • system hardware and software
  • system architecture
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • system developer
  • organizational personnel with boundary protection responsibilities

Test

  • Mechanisms supporting and/or implementing the prevention of discovery of system components at managed interfaces
Official NIST control enhancement

SC-7(17) — Automated Enforcement of Protocol Formats

Enforce adherence to protocol formats.

Official discussion

System components that enforce protocol formats include deep packet inspection firewalls and XML gateways. The components verify adherence to protocol formats and specifications at the application layer and identify vulnerabilities that cannot be detected by devices operating at the network or transport layers.

Assessment objectives and methods

adherence to protocol formats is enforced.

Examine

  • System and communications protection policy
  • procedures addressing boundary protection
  • system design documentation
  • system architecture
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • system developer
  • organizational personnel with boundary protection responsibilities

Test

  • Mechanisms supporting and/or implementing the enforcement of adherence to protocol formats
Related controls
Official NIST control enhancement

SC-7(18) — Fail Secure

High

Prevent systems from entering unsecure states in the event of an operational failure of a boundary protection device.

Official discussion

Fail secure is a condition achieved by employing mechanisms to ensure that in the event of operational failures of boundary protection devices at managed interfaces, systems do not enter into unsecure states where intended security properties no longer hold. Managed interfaces include routers, firewalls, and application gateways that reside on protected subnetworks (commonly referred to as demilitarized zones). Failures of boundary protection devices cannot lead to or cause information external to the devices to enter the devices nor can failures permit unauthorized information releases.

Assessment objectives and methods

systems are prevented from entering unsecure states in the event of an operational failure of a boundary protection device.

Examine

  • System and communications protection policy
  • procedures addressing boundary protection
  • system design documentation
  • system architecture
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • system developer
  • organizational personnel with boundary protection responsibilities

Test

  • Mechanisms supporting and/or implementing secure failure
Related controls
Official NIST control enhancement

SC-7(19) — Block Communication from Non-organizationally Configured Hosts

Block inbound and outbound communications traffic between [Organization-defined: communication clients] that are independently configured by end users and external service providers.

Official discussion

Communication clients independently configured by end users and external service providers include instant messaging clients and video conferencing software and applications. Traffic blocking does not apply to communication clients that are configured by organizations to perform authorized functions.

Organization-defined parameters (1)
communication clientscommunication clients that are independently configured by end users and external service providers are defined;
Assessment objectives and methods
  1. SC-07(19)[01]inbound communications traffic is blocked between [Organization-defined: communication clients] that are independently configured by end users and external service providers;
  2. SC-07(19)[02]outbound communications traffic is blocked between [Organization-defined: communication clients] that are independently configured by end users and external service providers.

Examine

  • System and communications protection policy
  • procedures addressing boundary protection
  • system design documentation
  • system hardware and software
  • system architecture
  • system configuration settings and associated documentation
  • list of communication clients independently configured by end users and external service providers
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel with boundary protection responsibilities

Test

  • Mechanisms supporting and/or implementing the blocking of inbound and outbound communications traffic between communication clients independently configured by end users and external service providers
Official NIST control enhancement

SC-7(20) — Dynamic Isolation and Segregation

Provide the capability to dynamically isolate [Organization-defined: system components] from other system components.

Official discussion

The capability to dynamically isolate certain internal system components is useful when it is necessary to partition or separate system components of questionable origin from components that possess greater trustworthiness. Component isolation reduces the attack surface of organizational systems. Isolating selected system components can also limit the damage from successful attacks when such attacks occur.

Organization-defined parameters (1)
system componentssystem components to be dynamically isolated from other system components are defined;
Assessment objectives and methods

the capability to dynamically isolate [Organization-defined: system components] from other system components is provided.

Examine

  • System and communications protection policy
  • procedures addressing boundary protection
  • system design documentation
  • system hardware and software
  • system architecture
  • system configuration settings and associated documentation
  • list of system components to be dynamically isolated/segregated from other components of the system
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • system developer
  • organizational personnel with boundary protection responsibilities

Test

  • Mechanisms supporting and/or implementing the capability to dynamically isolate/segregate system components
Official NIST control enhancement

SC-7(21) — Isolation of System Components

High

Employ boundary protection mechanisms to isolate [Organization-defined: system components] supporting [Organization-defined: missions and/or business functions].

Official discussion

Organizations can isolate system components that perform different mission or business functions. Such isolation limits unauthorized information flows among system components and provides the opportunity to deploy greater levels of protection for selected system components. Isolating system components with boundary protection mechanisms provides the capability for increased protection of individual system components and to more effectively control information flows between those components. Isolating system components provides enhanced protection that limits the potential harm from hostile cyber-attacks and errors. The degree of isolation varies depending upon the mechanisms chosen. Boundary protection mechanisms include routers, gateways, and firewalls that separate system components into physically separate networks or subnetworks; cross-domain devices that separate subnetworks; virtualization techniques; and the encryption of information flows among system components using distinct encryption keys.

Organization-defined parameters (2)
system componentssystem components to be isolated by boundary protection mechanisms are defined;
missions and/or business functionsmissions and/or business functions to be supported by system components isolated by boundary protection mechanisms are defined;
Assessment objectives and methods

boundary protection mechanisms are employed to isolate [Organization-defined: system components] supporting [Organization-defined: missions and/or business functions].

Examine

  • System and communications protection policy
  • procedures addressing boundary protection
  • system design documentation
  • system hardware and software
  • enterprise architecture documentation
  • system architecture
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel with boundary protection responsibilities

Test

  • Mechanisms supporting and/or implementing the capability to separate system components supporting organizational missions and/or business functions
Related controls
Official NIST control enhancement

SC-7(22) — Separate Subnets for Connecting to Different Security Domains

Implement separate network addresses to connect to systems in different security domains.

Official discussion

The decomposition of systems into subnetworks (i.e., subnets) helps to provide the appropriate level of protection for network connections to different security domains that contain information with different security categories or classification levels.

Assessment objectives and methods

separate network addresses are implemented to connect to systems in different security domains.

Examine

  • System and communications protection policy
  • procedures addressing boundary protection
  • system design documentation
  • system hardware and software
  • system architecture
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • system developer
  • organizational personnel with boundary protection responsibilities

Test

  • Mechanisms supporting and/or implementing separate network addresses/different subnets
Official NIST control enhancement

SC-7(23) — Disable Sender Feedback on Protocol Validation Failure

Disable feedback to senders on protocol format validation failure.

Official discussion

Disabling feedback to senders when there is a failure in protocol validation format prevents adversaries from obtaining information that would otherwise be unavailable.

Assessment objectives and methods

feedback to senders is disabled on protocol format validation failure.

Examine

  • System and communications protection policy
  • procedures addressing boundary protection
  • system design documentation
  • system hardware and software
  • system architecture
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • system developer
  • organizational personnel with boundary protection responsibilities

Test

  • Mechanisms supporting and/or implementing the disabling of feedback to senders on protocol format validation failure
Official NIST control enhancement

SC-7(24) — Personally Identifiable Information

Privacy

For systems that process personally identifiable information:

  1. (a)Apply the following processing rules to data elements of personally identifiable information: [Organization-defined: processing rules];
  2. (b)Monitor for permitted processing at the external interfaces to the system and at key internal boundaries within the system;
  3. (c)Document each processing exception; and
  4. (d)Review and remove exceptions that are no longer supported.
Official discussion

Managing the processing of personally identifiable information is an important aspect of protecting an individual’s privacy. Applying, monitoring for, and documenting exceptions to processing rules ensure that personally identifiable information is processed only in accordance with established privacy requirements.

Organization-defined parameters (1)
processing rulesprocessing rules for systems that process personally identifiable information are defined;
Assessment objectives and methods
  1. SC-07(24)(a)[Organization-defined: processing rules] are applied to data elements of personally identifiable information on systems that process personally identifiable information;
  2. SC-07(24)(b)
    1. SC-07(24)(b)[01]permitted processing is monitored at the external interfaces to the systems that process personally identifiable information;
    2. SC-07(24)(b)[02]permitted processing is monitored at key internal boundaries within the systems that process personally identifiable information;
  3. SC-07(24)(c)each processing exception is documented for systems that process personally identifiable information;
  4. SC-07(24)(d)
    1. SC-07(24)(d)[01]exceptions for systems that process personally identifiable information are reviewed;
    2. SC-07(24)(d)[02]exceptions for systems that process personally identifiable information that are no longer supported are removed.

Examine

  • System and communications protection policy
  • procedures addressing boundary protection
  • personally identifiable information processing policies
  • list of key internal boundaries of the system
  • system design documentation
  • system configuration settings and associated documentation
  • enterprise security and privacy architecture documentation
  • system audit records
  • system security plan
  • privacy plan
  • personally identifiable information inventory documentation
  • data mapping documentation
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security and privacy responsibilities
  • system developer
  • organizational personnel with boundary protection responsibilities

Test

  • Mechanisms implementing boundary protection capabilities
Related controls
Official NIST control enhancement

SC-7(25) — Unclassified National Security System Connections

Prohibit the direct connection of [Organization-defined: unclassified national security system] to an external network without the use of [Organization-defined: boundary protection device].

Official discussion

A direct connection is a dedicated physical or virtual connection between two or more systems. Organizations typically do not have complete control over external networks, including the Internet. Boundary protection devices (e.g., firewalls, gateways, and routers) mediate communications and information flows between unclassified national security systems and external networks.

Organization-defined parameters (2)
unclassified national security systemthe unclassified national security system prohibited from directly connecting to an external network is defined;
boundary protection devicethe boundary protection device required for a direct connection to an external network is defined;
Assessment objectives and methods

the direct connection of [Organization-defined: unclassified national security system] to an external network without the use of [Organization-defined: boundary protection device] is prohibited.

Examine

  • System and communications protection policy
  • procedures addressing boundary protection
  • system design documentation
  • system hardware and software
  • system architecture
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • system developer
  • organizational personnel with boundary protection responsibilities

Test

  • Mechanisms prohibiting the direct connection of unclassified national security systems to an external network
Official NIST control enhancement

SC-7(26) — Classified National Security System Connections

Prohibit the direct connection of a classified national security system to an external network without the use of [Organization-defined: boundary protection device].

Official discussion

A direct connection is a dedicated physical or virtual connection between two or more systems. Organizations typically do not have complete control over external networks, including the Internet. Boundary protection devices (e.g., firewalls, gateways, and routers) mediate communications and information flows between classified national security systems and external networks. In addition, approved boundary protection devices (typically managed interface or cross-domain systems) provide information flow enforcement from systems to external networks.

Organization-defined parameters (1)
boundary protection devicethe boundary protection device required for a direct connection to an external network is defined;
Assessment objectives and methods

the direct connection of classified national security system to an external network without the use of a [Organization-defined: boundary protection device] is prohibited.

Examine

  • System and communications protection policy
  • procedures addressing boundary protection
  • system design documentation
  • system hardware and software
  • system architecture
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • system developer
  • organizational personnel with boundary protection responsibilities

Test

  • Mechanisms prohibiting the direct connection of classified national security systems to an external network
Official NIST control enhancement

SC-7(27) — Unclassified Non-national Security System Connections

Prohibit the direct connection of [Organization-defined: unclassified, non-national security system] to an external network without the use of [Organization-defined: boundary protection device].

Official discussion

A direct connection is a dedicated physical or virtual connection between two or more systems. Organizations typically do not have complete control over external networks, including the Internet. Boundary protection devices (e.g., firewalls, gateways, and routers) mediate communications and information flows between unclassified non-national security systems and external networks.

Organization-defined parameters (2)
unclassified, non-national security systemthe unclassified, non-national security system prohibited from directly connecting to an external network is defined;
boundary protection devicethe boundary protection device required for a direct connection of unclassified, non-national security system to an external network is defined;
Assessment objectives and methods

the direct connection of [Organization-defined: unclassified, non-national security system] to an external network without the use of a [Organization-defined: boundary protection device] is prohibited.

Examine

  • System and communications protection policy
  • procedures addressing boundary protection
  • system design documentation
  • system hardware and software
  • system architecture
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • system developer
  • organizational personnel with boundary protection responsibilities

Test

  • Mechanisms prohibiting the direct connection of unclassified, non-national security systems to an external network
Official NIST control enhancement

SC-7(28) — Connections to Public Networks

Prohibit the direct connection of [Organization-defined: system] to a public network.

Official discussion

A direct connection is a dedicated physical or virtual connection between two or more systems. A public network is a network accessible to the public, including the Internet and organizational extranets with public access.

Organization-defined parameters (1)
systemthe system that is prohibited from directly connecting to a public network is defined;
Assessment objectives and methods

the direct connection of the [Organization-defined: system] to a public network is prohibited.

Examine

  • System and communications protection policy
  • procedures addressing boundary protection
  • system design documentation
  • system hardware and software
  • system architecture
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • system developer
  • organizational personnel with boundary protection responsibilities

Test

  • Mechanisms prohibiting the direct connection of systems to an external network
Official NIST control enhancement

SC-7(29) — Separate Subnets to Isolate Functions

Implement [Organization-defined: sc-07.29_odp.01] separate subnetworks to isolate the following critical system components and functions: [Organization-defined: critical system components and functions].

Official discussion

Separating critical system components and functions from other noncritical system components and functions through separate subnetworks may be necessary to reduce susceptibility to a catastrophic or debilitating breach or compromise that results in system failure. For example, physically separating the command and control function from the in-flight entertainment function through separate subnetworks in a commercial aircraft provides an increased level of assurance in the trustworthiness of critical system functions.

Organization-defined parameters (2)
sc-07.29_odp.01
critical system components and functionscritical system components and functions to be isolated are defined;
Assessment objectives and methods

subnetworks are separated [Organization-defined: sc-07.29_odp.01] to isolate [Organization-defined: critical system components and functions].

Examine

  • System and communications protection policy
  • procedures addressing boundary protection
  • system design documentation
  • system hardware and software
  • system architecture
  • system configuration settings and associated documentation
  • criticality analysis
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • system developer
  • organizational personnel with boundary protection responsibilities

Test

  • Mechanisms separating critical system components and functions
Source record

Authoritative sources