{"data":{"id":"SC-05","name":"Denial-of-service Protection","family":"SC","family_name":"System and Communications Protection","withdrawn":false,"description":"a. [Selection (one): Protect against; Limit] the effects of the following types of denial-of-service events: [Assignment: organization-defined types of denial-of-service events]; and\nb. Employ the following controls to achieve the denial-of-service objective: [Assignment: organization-defined controls by type of denial-of-service event].","supplemental_guidance":"Denial-of-service events may occur due to a variety of internal and external causes, such as an attack by an adversary or a lack of planning to support organizational needs with respect to capacity and bandwidth. Such attacks can occur across a wide range of network protocols (e.g., IPv4, IPv6). A variety of technologies are available to limit or eliminate the origination and effects of denial-of-service events. For example, boundary protection devices can filter certain types of packets to protect system components on internal networks from being directly affected by or the source of denial-of-service attacks. Employing increased network capacity and bandwidth combined with service redundancy also reduces the susceptibility to denial-of-service events.","enhancements":[{"id":"SC-05(01)","name":"Restrict Ability to Attack Other Systems","statement":"Restrict the ability of individuals to launch the following denial-of-service attacks against other systems: [Assignment: organization-defined denial-of-service attacks].","baselines":[]},{"id":"SC-05(02)","name":"Capacity, Bandwidth, and Redundancy","statement":"Manage capacity, bandwidth, or other redundancy to limit the effects of information flooding denial-of-service attacks.","baselines":[]},{"id":"SC-05(03)","name":"Detection and Monitoring","statement":"a. Employ the following monitoring tools to detect indicators of denial-of-service attacks against, or launched from, the system: [Assignment: organization-defined monitoring tools]; and\nb. Monitor the following system resources to determine if sufficient resources exist to prevent effective denial-of-service attacks: [Assignment: organization-defined system resources].","baselines":[]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"SC-05","name":"Denial-of-service Protection","description":"a. [Selection (one): Protect against; Limit] the effects of the following types of denial-of-service events: [Assignment: organization-defined types of denial-of-service events]; and\nb. Employ the following controls to achieve the denial-of-service objective: [Assignment: organization-defined controls by type of denial-of-service event].","discussion":"Denial-of-service events may occur due to a variety of internal and external causes, such as an attack by an adversary or a lack of planning to support organizational needs with respect to capacity and bandwidth. Such attacks can occur across a wide range of network protocols (e.g., IPv4, IPv6). A variety of technologies are available to limit or eliminate the origination and effects of denial-of-service events. For example, boundary protection devices can filter certain types of packets to protect system components on internal networks from being directly affected by or the source of denial-of-service attacks. Employing increased network capacity and bandwidth combined with service redundancy also reduces the susceptibility to denial-of-service events.","related_controls":["CP-02","IR-04","SC-06","SC-07","SC-40"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"Adds 'Selection: protect against; limit the effects of the following types of denial of service events' Changes parameter to specific types of denial of service events Parameter removes 'or reference to sources for such information' Changes control text from 'employing  security safeguards' to 'Employ the following controls to achieve the denial of service objective' Discussion amplifies definition of denial of service events"}},"compliance_mappings":{"iso_27001_2022":["A.8.6"],"iso_27002_2022":["8.6"],"cobit_2019":["BAI04"],"pci_dss_v4":[],"nist_csf_2":["DE.CM-01","PR.IR-01","PR.IR-03","PR.IR-04"],"cis_controls_v8":[],"soc2_tsc":["A1.1","A1.1-POF1"],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":["3-3 SR 7.1","3-3 SR 7.2"],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":["Hygiene.22","Hygiene.27","SecNumCloud.14.4"],"osfi_b13":["B-13.2.6","B-13.3.2"],"finma_circular":["IV.B.d(59)","IV.C(62)","IV.C(65)"],"gdpr":["Art.32(1)(b)"],"dora":["Art.9(2)"],"bio2":["8.6"],"rbi_csf":["Annex1.4","Annex1.13"],"fisc":["FISC.T3"],"lgpd_bcb":[],"hkma_tme1":[],"mlps_2":[],"dnb_good_practice":["DNB.18.1"],"cra":["CRA.I.2h"],"swift_cscf":[],"cbb_tm":["TM-8"],"cbuae":["CR-7"],"nca_ecc":["2-5"],"qatar_nia":["CS"],"sama_csf":["3.3"],"uae_ia":["T7"],"bog_cisd":["CISD-VI"],"cbe_csf":["CTO-6"],"cbn_csf":["Part3.3"],"sa_js2":["JS2-7.2"],"bcbs_239":["Principle 5"],"bot_cyber":["Ch2.4"],"cpmi_pfmi":["CG.DE","PFMI.P17"],"eba_ict":["3.5(a)"],"ecb_croe":["CROE.2.3.5","CROE.2.4"],"iosco_cyber":["DET-2"],"sebi_cscrf":["PR.NS"],"cmmc_2":["SC"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":["CC Part 2 — FRU/FTA/FTP"],"isae_3402":[],"fca_sysc_13":["SYSC 13.7.2","SYSC 13.8.2"],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":["09.e"],"iso_27799":[],"lloyds_ms":["MS8.9"],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":["EIOPA-ICT-4.6"],"owasp_masvs_v2":[],"csa_ccm_v4":["IVS-02","IVS-09"],"csa_aicm":["I&S-02","I&S-09"],"ccss_v9":[],"mica":["Art.62(5)","Art.68(1)","Art.68(5)"],"basel_sco60":["SCO60.51","SCO60.53","SCO60.65"],"bssc":["NOS-04"],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1496.003","name":"SMS Pumping","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Denial-of-service protection mechanisms—including rate limiting, traffic filtering, and SMS gateway controls—directly mitigate SMS pumping attacks by detecting and blocking artificially inflated messaging volumes that generate fraudulent toll charges."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: nist_csf_2 DE.CM-01, PR.IR-01 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-001","SP-002","SP-005","SP-008","SP-011","SP-016"]}}