SC-05 Denial-of-service Protection
System and Communications Protection
Description
a. [Selection (one): Protect against; Limit] the effects of the following types of denial-of-service events: [Assignment: organization-defined types of denial-of-service events]; and b. Employ the following controls to achieve the denial-of-service objective: [Assignment: organization-defined controls by type of denial-of-service event].
Supplemental Guidance
Denial-of-service events may occur due to a variety of internal and external causes, such as an attack by an adversary or a lack of planning to support organizational needs with respect to capacity and bandwidth. Such attacks can occur across a wide range of network protocols (e.g., IPv4, IPv6). A variety of technologies are available to limit or eliminate the origination and effects of denial-of-service events. For example, boundary protection devices can filter certain types of packets to protect system components on internal networks from being directly affected by or the source of denial-of-service attacks. Employing increased network capacity and bandwidth combined with service redundancy also reduces the susceptibility to denial-of-service events.
Changes from Rev 4
Adds 'Selection: protect against; limit the effects of the following types of denial of service events' Changes parameter to specific types of denial of service events Parameter removes 'or reference to sources for such information' Changes control text from 'employing security safeguards' to 'Employ the following controls to achieve the denial of service objective' Discussion amplifies definition of denial of service events
Enhancements (3)
What NIST adds to this control. Select one to read its statement.
SC-05(01) Restrict Ability to Attack Other Systems
Restrict the ability of individuals to launch the following denial-of-service attacks against other systems: [Assignment: organization-defined denial-of-service attacks].
SC-05(02) Capacity, Bandwidth, and Redundancy
Manage capacity, bandwidth, or other redundancy to limit the effects of information flooding denial-of-service attacks.
SC-05(03) Detection and Monitoring
a. Employ the following monitoring tools to detect indicators of denial-of-service attacks against, or launched from, the system: [Assignment: organization-defined monitoring tools]; and b. Monitor the following system resources to determine if sufficient resources exist to prevent effective denial-of-service attacks: [Assignment: organization-defined system resources].
Patterns that use this control (6)
Grouped by the emphasis each pattern gives it.
Critical (1)
Important (4)
Standard (1)
MITRE ATT&CK Techniques (1)
ATT&CK v16.1Techniques mitigated by this control, mapped via CTID.