# SC-05 Denial-of-service Protection

NIST SP 800-53 control. Family: SC System and Communications Protection. Function: preventative. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: a. [Selection (one): Protect against; Limit] the effects of the following types of denial-of-service events: [Assignment: organization-defined types of denial-of-service events]; and b. Employ the following controls to achieve the denial-of-service objective: [Assignment: organization-defined controls by type of denial-of-service event].
Guidance: Denial-of-service events may occur due to a variety of internal and external causes, such as an attack by an adversary or a lack of planning to support organizational needs with respect to capacity and bandwidth. Such attacks can occur across a wide range of network protocols (e.g., IPv4, IPv6). A variety of technologies are available to limit or eliminate the origination and effects of denial-of-service events. For example, boundary protection devices can filter certain types of packets to protect system components on internal networks from being directly affected by or the source of denial-of-service attacks. Employing increased network capacity and bandwidth combined with service redundancy also reduces the susceptibility to denial-of-service events.

## Enhancements (3)
- SC-05(01) Restrict Ability to Attack Other Systems
- SC-05(02) Capacity, Bandwidth, and Redundancy
- SC-05(03) Detection and Monitoring
Each enhancement's statement: /api/v1/controls/SC-05?fields=enhancements

## Patterns that use it (6)
- Critical (1): SP-008 Public Web Server Pattern
- Important (4): SP-002 Server Module; SP-005 SOA Internal Service Usage Pattern; SP-011 Cloud Computing Pattern; SP-016 DMZ Module
- Standard (1): SP-001 Client Module

## Clauses by framework (44 frameworks)
- iso_27001_2022: A.8.6. OSA's own, not in NIST's crosswalk: A.8.6
- iso_27002_2022: 8.6
- cobit_2019: BAI04
- nist_csf_2: DE.CM-01, PR.IR-01, PR.IR-03, PR.IR-04. OSA's own, not in NIST's crosswalk: PR.IR-03, PR.IR-04
- soc2_tsc: A1.1, A1.1-POF1
- iec_62443: 3-3 SR 7.1, 3-3 SR 7.2
- anssi: Hygiene.22, Hygiene.27, SecNumCloud.14.4
- osfi_b13: B-13.2.6, B-13.3.2
- finma_circular: IV.B.d(59), IV.C(62), IV.C(65)
- gdpr: Art.32(1)(b)
- dora: Art.9(2)
- bio2: 8.6
- rbi_csf: Annex1.4, Annex1.13
- fisc: FISC.T3
- dnb_good_practice: DNB.18.1
- cra: CRA.I.2h
- cbb_tm: TM-8
- cbuae: CR-7
- nca_ecc: 2-5
- qatar_nia: CS
- sama_csf: 3.3
- uae_ia: T7
- bog_cisd: CISD-VI
- cbe_csf: CTO-6
- cbn_csf: Part3.3
- sa_js2: JS2-7.2
- bcbs_239: Principle 5
- bot_cyber: Ch2.4
- cpmi_pfmi: CG.DE, PFMI.P17
- eba_ict: 3.5(a)
- ecb_croe: CROE.2.3.5, CROE.2.4
- iosco_cyber: DET-2
- sebi_cscrf: PR.NS
- cmmc_2: SC
- common_criteria: CC Part 2 — FRU/FTA/FTP
- fca_sysc_13: SYSC 13.7.2, SYSC 13.8.2
- hitrust_csf: 09.e
- lloyds_ms: MS8.9
- solvency_ii: EIOPA-ICT-4.6
- csa_ccm_v4: IVS-02, IVS-09
- csa_aicm: I&S-02, I&S-09
- mica: Art.62(5), Art.68(1), Art.68(5)
- basel_sco60: SCO60.51, SCO60.53, SCO60.65
- bssc: NOS-04
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/SC-05
- Clauses only: /api/v1/controls/SC-05?fields=mappings
- Page for people: /controls/sc-05/
