← Controls / SC

SC-07 Boundary Protection

System and Communications Protection

Low Moderate High

Description

a. Monitor and control communications at the external managed interfaces to the system and at key internal managed interfaces within the system; b. Implement subnetworks for publicly accessible system components that are [Selection (one): physically; logically] separated from internal organizational networks; and c. Connect to external networks or systems only through managed interfaces consisting of boundary protection devices arranged in accordance with an organizational security and privacy architecture.

Supplemental Guidance

Managed interfaces include gateways, routers, firewalls, guards, network-based malicious code analysis, virtualization systems, or encrypted tunnels implemented within a security architecture. Subnetworks that are physically or logically separated from internal networks are referred to as demilitarized zones or DMZs. Restricting or prohibiting interfaces within organizational systems includes restricting external web traffic to designated web servers within managed interfaces, prohibiting external traffic that appears to be spoofing internal addresses, and prohibiting internal traffic that appears to be spoofing external addresses. [SP 800-189] provides additional information on source address validation techniques to prevent ingress and egress of traffic with spoofed addresses. Commercial telecommunications services are provided by network components and consolidated management systems shared by customers. These services may also include third party-provided access lines and other service elements. Such services may represent sources of increased risk despite contract security provisions. Boundary protection may be implemented as a common control for all or part of an organizational network such that the boundary to be protected is greater than a system-specific boundary (i.e., an authorization boundary).

Changes from Rev 4

Control text changes 'boundary' to 'managed interfaces; adds 'and privacy' in reference to organizational security architecture

Enhancements (26)

What NIST adds to this control. Select one to read its statement.

SC-07(03) Access Points ModerateHigh

Limit the number of external network connections to the system.

SC-07(04) External Telecommunications Services ModerateHigh

a. Implement a managed interface for each external telecommunication service; b. Establish a traffic flow policy for each managed interface; c. Protect the confidentiality and integrity of the information being transmitted across each interface; d. Document each exception to the traffic flow policy with a supporting mission or business need and duration of that need; e. Review exceptions to the traffic flow policy [Assignment: organization-defined frequency] and remove exceptions that are no longer supported by an explicit mission or business need; f. Prevent unauthorized exchange of control plane traffic with external networks; g. Publish information to enable remote networks to detect unauthorized control plane traffic from internal networks; and h. Filter unauthorized control plane traffic from external networks.

SC-07(05) Deny by Default — Allow by Exception ModerateHigh

Deny network communications traffic by default and allow network communications traffic by exception [Selection (one or more): at managed interfaces; for [Assignment: organization-defined systems]].

SC-07(07) Split Tunneling for Remote Devices ModerateHigh

Prevent split tunneling for remote devices connecting to organizational systems unless the split tunnel is securely provisioned using [Assignment: organization-defined safeguards].

SC-07(08) Route Traffic to Authenticated Proxy Servers ModerateHigh

Route [Assignment: organization-defined internal communications traffic] to [Assignment: organization-defined external networks] through authenticated proxy servers at managed interfaces.

SC-07(09) Restrict Threatening Outgoing Communications Traffic

a. Detect and deny outgoing communications traffic posing a threat to external systems; and b. Audit the identity of internal users associated with denied communications.

SC-07(10) Prevent Exfiltration

a. Prevent the exfiltration of information; and b. Conduct exfiltration tests [Assignment: organization-defined frequency].

SC-07(11) Restrict Incoming Communications Traffic

Only allow incoming communications from [Assignment: organization-defined authorized sources] to be routed to [Assignment: organization-defined authorized destinations].

SC-07(12) Host-based Protection

Implement [Assignment: organization-defined host-based boundary protection mechanisms] at [Assignment: organization-defined system components].

SC-07(13) Isolation of Security Tools, Mechanisms, and Support Components

Isolate [Assignment: organization-defined information security tools, mechanisms, and support components] from other internal system components by implementing physically separate subnetworks with managed interfaces to other components of the system.

SC-07(14) Protect Against Unauthorized Physical Connections

Protect against unauthorized physical connections at [Assignment: organization-defined managed interfaces].

SC-07(15) Networked Privileged Accesses

Route networked, privileged accesses through a dedicated, managed interface for purposes of access control and auditing.

SC-07(16) Prevent Discovery of System Components

Prevent the discovery of specific system components that represent a managed interface.

SC-07(17) Automated Enforcement of Protocol Formats

Enforce adherence to protocol formats.

SC-07(18) Fail Secure High

Prevent systems from entering unsecure states in the event of an operational failure of a boundary protection device.

SC-07(19) Block Communication from Non-organizationally Configured Hosts

Block inbound and outbound communications traffic between [Assignment: organization-defined communication clients] that are independently configured by end users and external service providers.

SC-07(20) Dynamic Isolation and Segregation

Provide the capability to dynamically isolate [Assignment: organization-defined system components] from other system components.

SC-07(21) Isolation of System Components High

Employ boundary protection mechanisms to isolate [Assignment: organization-defined system components] supporting [Assignment: organization-defined missions and/or business functions].

SC-07(22) Separate Subnets for Connecting to Different Security Domains

Implement separate network addresses to connect to systems in different security domains.

SC-07(23) Disable Sender Feedback on Protocol Validation Failure

Disable feedback to senders on protocol format validation failure.

SC-07(24) Personally Identifiable Information Privacy

For systems that process personally identifiable information: a. Apply the following processing rules to data elements of personally identifiable information: [Assignment: organization-defined processing rules]; b. Monitor for permitted processing at the external interfaces to the system and at key internal boundaries within the system; c. Document each processing exception; and d. Review and remove exceptions that are no longer supported.

SC-07(25) Unclassified National Security System Connections

Prohibit the direct connection of [Assignment: organization-defined unclassified national security system] to an external network without the use of [Assignment: organization-defined boundary protection device].

SC-07(26) Classified National Security System Connections

Prohibit the direct connection of a classified national security system to an external network without the use of [Assignment: organization-defined boundary protection device].

SC-07(27) Unclassified Non-national Security System Connections

Prohibit the direct connection of [Assignment: organization-defined unclassified non-national security system] to an external network without the use of [Assignment: organization-defined boundary protection device].

SC-07(28) Connections to Public Networks

Prohibit the direct connection of [Assignment: organization-defined system] to a public network.

SC-07(29) Separate Subnets to Isolate Functions

Implement [Selection (one): physically; logically] separate subnetworks to isolate the following critical system components and functions: [Assignment: organization-defined critical system components and functions].

Withdrawn by NIST:

  • SC-07(01) Physically Separated Subnetworks, now in SC-07
  • SC-07(02) Public Access, now in SC-07
  • SC-07(06) Response to Recognized Failures, now in SC-07(18)

MITRE ATT&CK Techniques (156)

ATT&CK v16.1

Techniques mitigated by this control, mapped via CTID.

Reconnaissance 5 Initial Access 10 Execution 12 Persistence 15 Privilege Escalation 17 Defense Evasion 30 Credential Access 12 Discovery 4 Lateral Movement 11 Collection 13 Command & Control 36 Exfiltration 14 Impact 12
Show all 156 techniques grouped by tactic

Defense Evasion

Command & Control

Compliance Mappings

ISO 27001:2022

A.5.14A.5.23A.8.12A.8.16A.8.20A.8.21A.8.22A.8.23A.8.27

ISO 27002:2022

5.145.238.128.208.218.228.238.27

COBIT 2019

DSS05

CIS Controls v8

CIS 3.12CIS 3.13CIS 4CIS 4.2CIS 4.4CIS 4.5CIS 9CIS 9.2CIS 9.3CIS 9.6CIS 12CIS 12.2CIS 12.8CIS 13CIS 13.3CIS 13.4CIS 13.8CIS 13.9CIS 13.10

NIST CSF 2.0

DE.CM-01ID.AM-03PR.DS-01PR.DS-02PR.DS-10PR.IR-01RS.MI-01

SOC 2 TSC

CC6.1CC6.1-POF5CC6.6CC6.6-POF1CC6.6-POF3CC6.8

PCI DSS v4.0.1

1.11.21.2.11.2.51.31.41.55.46.4

CSA CCM v4

IVS-03IVS-05IVS-06IVS-08IVS-09UEM-10UEM-11

CSA AICM v1

AIS-08I&S-03I&S-05I&S-06I&S-08I&S-09IAM-17UEM-10UEM-11

FINOS CCC

CCC-C05CCC-C09

IEC 62443

3-3 SR 5.13-3 SR 5.2

PRA Operational Resilience

SS2/21-14.1

MAS TRM

111415

APRA CPS 234

Para 22-23

ASD Essential Eight

E8-5 ML2

BSI IT-Grundschutz

APP.3.1NET.1.1NET.1.2NET.3.1

ANSSI

Hygiene.22Hygiene.23Hygiene.27SecNumCloud.14.1SecNumCloud.14.4

FINMA Circular 2023/1

IV.B.d(59)IV.C(62)IV.C(63)

OSFI B-13

B-13.3.2

EU GDPR

Art.5(1)(f)Art.32(1)(a)Art.32(1)(b)

EU DORA

Art.9(4)(a)

BIO2

5.145.238.128.208.218.228.238.27

RBI CSF

Annex1.4Annex1.15ITGRCA.19

FISC Security Guidelines

FISC.T3FISC.T8FISC.T9FISC.T10FISC.T11FISC.T13

LGPD + BCB 4893

BCB.Art.3BCB.Art.13BCB.OpenFinanceBCB.PIXLGPD.Art.46

HKMA TM-E-1

TME1.7.3TME1.10.1TME1.10.3TME1.12.4

MLPS 2.0

8.1.2.18.1.3.18.1.3.28.1.3.38.28.38.5

DNB Good Practice

DNB.18.1DNB.18.4DNB.20.1

EU CRA

CRA.I.2iCRA.I.2j

SWIFT CSCF

SWIFT.1.1SWIFT.1.3SWIFT.1.4SWIFT.1.5SWIFT.2.3SWIFT.6.5A

SAMA CSF

2.13.34.3

NCA ECC

2-32-42-52-144-25-1

UAE IA

T8

CBB TM

TM-8

Qatar NIA

CS

CBUAE

CR-7

CBE CSF

CRM-2CTO-5CTO-6CTO-8CTO-11

SA JS2

JS2-7.2JS2-7.6

CBN CSF

Part3.1Part3.3Part5.1Part5.2

BoG CISD

CISD-IXCISD-VICISD-VIIICISD-XICISD-XIICISD-XIII

POPIA

s19s72

BoM CTRM

3.23.13

IOSCO Cyber Resilience

DET-4PFMI-20PROT-2

BCBS 239

Principle 2

CPMI-IOSCO PFMI

CG.DECG.PRPFMI.P17PFMI.P22

FFIEC IS

II.C.2II.C.6II.C.9II.C.12II.C.16

NYDFS 500

500.2500.14

HIPAA Security Rule

§164.308(a)(4)(ii)(A)§164.312(e)(1)§164.314(b)(1)§164.314(b)(2)

ECB CROE

CROE.2.3.5CROE.2.4

EBA ICT Guidelines

3.4.4

SEBI CSCRF

EMAIL-SECPR.CSPR.NS

BOT Cyber Resilience

Ch2.4Ch5.2Ch8.2Ch9.1

CMMC 2.0

SC

NERC CIP

CIP-002-7CIP-005-7CIP-015-1

10 CFR 73.54

73.54(c)(1)73.54(c)(2)RG5.71-A-SC

TSA Pipeline SD

SD-2 Sec ASD-2 Sec F

IEEE 1686-2022

5.6

FERC CIP Orders

Order 881Order 887Order 2222

DOE C2M2 v2.1

ARCHITECTURE

API 1164

Sec 5

AWIA

AWWA Sec 4

IAEA NSS 17-T

Sec 5.1Sec 5.6

PCI PTS v6

E

FIPS 140-3

FIPS 140-3 §7.3

CBEST

CBEST.5

Common Criteria

CC Part 2 — FDPCC Part 2 — FPT

ISAE 3402

Clause 4

Solvency II

EIOPA-ICT-4.6

Lloyd's Minimum Standards

MS8.9

NAIC Insurance Data Security

44-monitoring4B

PRA SS1/23

P-IT.3

FCA SYSC 13

SYSC 13.7.3

HITRUST CSF v11

01.b01.d05.c09.e

FDA 21 CFR Part 11

§11.30

FDA Cybersecurity Guidance

PU-3TM-2

ISO 27799

13.1H.2H.3

NHS DSPT

NDG-9.2NDG-9.4NDG-9.5

OWASP MASVS v2.1

MASVS-NETWORK-1MASVS-PLATFORM-1MASVS-PLATFORM-2

MiCA

Art.62(5)Art.68(1)

Basel SCO60

SCO60.21SCO60.41SCO60.51SCO60.64SCO60.65

BSSC Standards

NOS-04TIS-04

SEC Custody (Digital Assets)

SEC-CD-09

India DPDPA

Act.8(5)Rules.13(4)Rules.Sch1.B.7

ISO 17799 (legacy)

11.4.6

COBIT 4.1 (legacy)

DS5.10