# SC-07 Boundary Protection

NIST SP 800-53 control. Family: SC System and Communications Protection. Function: preventative. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: a. Monitor and control communications at the external managed interfaces to the system and at key internal managed interfaces within the system; b. Implement subnetworks for publicly accessible system components that are [Selection (one): physically; logically] separated from internal organizational networks; and c. Connect to external networks or systems only through managed interfaces consisting of boundary protection devices arranged in accordance with an organizational security and privacy architecture.
Guidance: Managed interfaces include gateways, routers, firewalls, guards, network-based malicious code analysis, virtualization systems, or encrypted tunnels implemented within a security architecture. Subnetworks that are physically or logically separated from internal networks are referred to as demilitarized zones or DMZs. Restricting or prohibiting interfaces within organizational systems includes restricting external web traffic to designated web servers within managed interfaces, prohibiting external traffic that appears to be spoofing internal addresses, and prohibiting internal traffic that appears to be spoofing external addresses. [SP 800-189] provides additional information on source address validation techniques to prevent ingress and egress of traffic with spoofed addresses. Commercial telecommunications services are provided by network components and consolidated management systems shared by customers. These services may also include third party-provided access lines and other service elements. Such services may represent sources of increased risk despite contract security provisions. Boundary protection may be implemented as a common control for all or part of an organizational network such that the boundary to be protected is greater than a system-specific boundary (i.e., an authorization boundary).

## Enhancements (26)
- SC-07(03) Access Points. Baselines: moderate, high
- SC-07(04) External Telecommunications Services. Baselines: moderate, high
- SC-07(05) Deny by Default — Allow by Exception. Baselines: moderate, high
- SC-07(07) Split Tunneling for Remote Devices. Baselines: moderate, high
- SC-07(08) Route Traffic to Authenticated Proxy Servers. Baselines: moderate, high
- SC-07(09) Restrict Threatening Outgoing Communications Traffic
- SC-07(10) Prevent Exfiltration
- SC-07(11) Restrict Incoming Communications Traffic
- SC-07(12) Host-based Protection
- SC-07(13) Isolation of Security Tools, Mechanisms, and Support Components
- SC-07(14) Protect Against Unauthorized Physical Connections
- SC-07(15) Networked Privileged Accesses
- SC-07(16) Prevent Discovery of System Components
- SC-07(17) Automated Enforcement of Protocol Formats
- SC-07(18) Fail Secure. Baselines: high
- SC-07(19) Block Communication from Non-organizationally Configured Hosts
- SC-07(20) Dynamic Isolation and Segregation
- SC-07(21) Isolation of System Components. Baselines: high
- SC-07(22) Separate Subnets for Connecting to Different Security Domains
- SC-07(23) Disable Sender Feedback on Protocol Validation Failure
- SC-07(24) Personally Identifiable Information. Baselines: privacy
- SC-07(25) Unclassified National Security System Connections
- SC-07(26) Classified National Security System Connections
- SC-07(27) Unclassified Non-national Security System Connections
- SC-07(28) Connections to Public Networks
- SC-07(29) Separate Subnets to Isolate Functions
Withdrawn by NIST: SC-07(01) (now in SC-07); SC-07(02) (now in SC-07); SC-07(06) (now in SC-07(18)).
Each enhancement's statement: /api/v1/controls/SC-07?fields=enhancements

## Patterns that use it (29)
- Critical (12): SP-015 Secure Remote Working; SP-017 Secure Network Zone Module; SP-019 Secure Ad-Hoc File Exchange Pattern; SP-023 Industrial Control Systems; SP-026 PCI Full Environment; SP-027 Secure LLM Usage; SP-029 Zero Trust Architecture; SP-030 API Security; SP-034 Cyber Resilience; SP-047 Secure Agentic AI Frameworks; SP-051 Tokenised Asset Security Architecture (draft); SP-054 CBDC and Digital Currency Infrastructure (draft)
- Important (13): SP-011 Cloud Computing Pattern; SP-013 Data Security Pattern; SP-020 Email Transport Layer Security (TLS) Pattern; SP-025 Advanced Monitoring and Detection; SP-028 Secure DevOps Pipeline Pattern; SP-031 Security Monitoring and Response; SP-035 Offensive Security Testing; SP-036 Incident Response; SP-037 Privileged User Management; SP-038 Vulnerability Management and Patching; SP-042 Third Party Risk Management; SP-046 External Attack Surface Management; SP-053 Zero-Knowledge Proof Architecture (draft)
- Standard (4): SP-012 Secure Software Development Lifecycle; SP-039 Client-Side Encryption and Data Privacy; SP-040 Post-Quantum Cryptography and Quantum Readiness; SP-050 Mobile Security Architecture (draft)

## Clauses by framework (83 frameworks)
- iso_27001_2022: A.5.14, A.5.23, A.8.12, A.8.16, A.8.20, A.8.21, A.8.22, A.8.23, A.8.27. OSA's own, not in NIST's crosswalk: A.5.23, A.8.12, A.8.21, A.8.27
- iso_27002_2022: 5.14, 5.23, 8.12, 8.20, 8.21, 8.22, 8.23, 8.27
- cobit_2019: DSS05
- pci_dss_v4: 1.1, 1.2, 1.2.1, 1.2.5, 1.3, 1.4, 1.5, 5.4, 6.4
- nist_csf_2: DE.CM-01, ID.AM-03, PR.DS-01, PR.DS-02, PR.DS-10, PR.IR-01, RS.MI-01. OSA's own, not in NIST's crosswalk: ID.AM-03, RS.MI-01
- cis_controls_v8: CIS 3.12, CIS 3.13, CIS 4, CIS 4.2, CIS 4.4, CIS 4.5, CIS 9, CIS 9.2, CIS 9.3, CIS 9.6, CIS 12, CIS 12.2, CIS 12.8, CIS 13, CIS 13.3, CIS 13.4, CIS 13.8, CIS 13.9, CIS 13.10
- soc2_tsc: CC6.1, CC6.1-POF5, CC6.6, CC6.6-POF1, CC6.6-POF3, CC6.8
- finos_ccc: CCC-C05, CCC-C09
- iec_62443: 3-3 SR 5.1, 3-3 SR 5.2
- asd_e8: E8-5 ML2
- apra_cps_234: Para 22-23
- mas_trm: 11, 14, 15
- pra_op_resilience: SS2/21-14.1
- bsi_grundschutz: APP.3.1, NET.1.1, NET.1.2, NET.3.1
- anssi: Hygiene.22, Hygiene.23, Hygiene.27, SecNumCloud.14.1, SecNumCloud.14.4
- osfi_b13: B-13.3.2
- finma_circular: IV.B.d(59), IV.C(62), IV.C(63)
- gdpr: Art.5(1)(f), Art.32(1)(a), Art.32(1)(b)
- dora: Art.9(4)(a)
- bio2: 5.14, 5.23, 8.12, 8.20, 8.21, 8.22, 8.23, 8.27
- rbi_csf: Annex1.4, Annex1.15, ITGRCA.19
- fisc: FISC.T3, FISC.T8, FISC.T9, FISC.T10, FISC.T11, FISC.T13
- lgpd_bcb: BCB.Art.3, BCB.Art.13, BCB.OpenFinance, BCB.PIX, LGPD.Art.46
- hkma_tme1: TME1.7.3, TME1.10.1, TME1.10.3, TME1.12.4
- mlps_2: 8.1.2.1, 8.1.3.1, 8.1.3.2, 8.1.3.3, 8.2, 8.3, 8.5
- dnb_good_practice: DNB.18.1, DNB.18.4, DNB.20.1
- cra: CRA.I.2i, CRA.I.2j
- swift_cscf: SWIFT.1.1, SWIFT.1.3, SWIFT.1.4, SWIFT.1.5, SWIFT.2.3, SWIFT.6.5A
- cbb_tm: TM-8
- cbuae: CR-7
- nca_ecc: 2-3, 2-4, 2-5, 2-14, 4-2, 5-1
- qatar_nia: CS
- sama_csf: 2.1, 3.3, 4.3
- uae_ia: T8
- bog_cisd: CISD-IX, CISD-VI, CISD-VIII, CISD-XI, CISD-XII, CISD-XIII
- bom_ctrm: 3.2, 3.13
- cbe_csf: CRM-2, CTO-5, CTO-6, CTO-8, CTO-11
- cbn_csf: Part3.1, Part3.3, Part5.1, Part5.2
- popia: s19, s72
- sa_js2: JS2-7.2, JS2-7.6
- bcbs_239: Principle 2
- bot_cyber: Ch2.4, Ch5.2, Ch8.2, Ch9.1
- cpmi_pfmi: CG.DE, CG.PR, PFMI.P17, PFMI.P22
- eba_ict: 3.4.4
- ecb_croe: CROE.2.3.5, CROE.2.4
- ffiec_is: II.C.2, II.C.6, II.C.9, II.C.12, II.C.16
- hipaa_sr: §164.308(a)(4)(ii)(A), §164.312(e)(1), §164.314(b)(1), §164.314(b)(2)
- iosco_cyber: DET-4, PFMI-20, PROT-2
- nydfs_500: 500.2, 500.14
- sebi_cscrf: EMAIL-SEC, PR.CS, PR.NS
- cmmc_2: SC
- nerc_cip: CIP-002-7, CIP-005-7, CIP-015-1
- nrc_73_54: 73.54(c)(1), 73.54(c)(2), RG5.71-A-SC
- tsa_psd: SD-2 Sec A, SD-2 Sec F
- ieee_1686: 5.6
- ferc_cip: Order 881, Order 887, Order 2222
- doe_c2m2: ARCHITECTURE
- api_1164: Sec 5
- awia: AWWA Sec 4
- iaea_nss: Sec 5.1, Sec 5.6
- pci_pts: E
- fips_140: FIPS 140-3 §7.3
- cbest: CBEST.5
- common_criteria: CC Part 2 — FDP, CC Part 2 — FPT
- isae_3402: Clause 4
- fca_sysc_13: SYSC 13.7.3
- fda_21_cfr_11: §11.30
- fda_cyber: PU-3, TM-2
- hitrust_csf: 01.b, 01.d, 05.c, 09.e
- iso_27799: 13.1, H.2, H.3
- lloyds_ms: MS8.9
- naic_ds: 4, 4-monitoring, 4B
- nhs_dspt: NDG-9.2, NDG-9.4, NDG-9.5
- pra_ss1_23: P-IT.3
- solvency_ii: EIOPA-ICT-4.6
- owasp_masvs_v2: MASVS-NETWORK-1, MASVS-PLATFORM-1, MASVS-PLATFORM-2
- csa_ccm_v4: IVS-03, IVS-05, IVS-06, IVS-08, IVS-09, UEM-10, UEM-11
- csa_aicm: AIS-08, I&S-03, I&S-05, I&S-06, I&S-08, I&S-09, IAM-17, UEM-10, UEM-11
- mica: Art.62(5), Art.68(1)
- basel_sco60: SCO60.21, SCO60.41, SCO60.51, SCO60.64, SCO60.65
- bssc: NOS-04, TIS-04
- sec_custody_digital: SEC-CD-09
- dpdpa: Act.8(5), Rules.13(4), Rules.Sch1.B.7
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/SC-07
- Clauses only: /api/v1/controls/SC-07?fields=mappings
- Page for people: /controls/sc-07/
