SC-07 Boundary Protection
System and Communications Protection
Description
a. Monitor and control communications at the external managed interfaces to the system and at key internal managed interfaces within the system; b. Implement subnetworks for publicly accessible system components that are [Selection (one): physically; logically] separated from internal organizational networks; and c. Connect to external networks or systems only through managed interfaces consisting of boundary protection devices arranged in accordance with an organizational security and privacy architecture.
Supplemental Guidance
Managed interfaces include gateways, routers, firewalls, guards, network-based malicious code analysis, virtualization systems, or encrypted tunnels implemented within a security architecture. Subnetworks that are physically or logically separated from internal networks are referred to as demilitarized zones or DMZs. Restricting or prohibiting interfaces within organizational systems includes restricting external web traffic to designated web servers within managed interfaces, prohibiting external traffic that appears to be spoofing internal addresses, and prohibiting internal traffic that appears to be spoofing external addresses. [SP 800-189] provides additional information on source address validation techniques to prevent ingress and egress of traffic with spoofed addresses. Commercial telecommunications services are provided by network components and consolidated management systems shared by customers. These services may also include third party-provided access lines and other service elements. Such services may represent sources of increased risk despite contract security provisions. Boundary protection may be implemented as a common control for all or part of an organizational network such that the boundary to be protected is greater than a system-specific boundary (i.e., an authorization boundary).
Changes from Rev 4
Control text changes 'boundary' to 'managed interfaces; adds 'and privacy' in reference to organizational security architecture
Enhancements (26)
What NIST adds to this control. Select one to read its statement.
SC-07(03) Access Points ModerateHigh
Limit the number of external network connections to the system.
SC-07(04) External Telecommunications Services ModerateHigh
a. Implement a managed interface for each external telecommunication service; b. Establish a traffic flow policy for each managed interface; c. Protect the confidentiality and integrity of the information being transmitted across each interface; d. Document each exception to the traffic flow policy with a supporting mission or business need and duration of that need; e. Review exceptions to the traffic flow policy [Assignment: organization-defined frequency] and remove exceptions that are no longer supported by an explicit mission or business need; f. Prevent unauthorized exchange of control plane traffic with external networks; g. Publish information to enable remote networks to detect unauthorized control plane traffic from internal networks; and h. Filter unauthorized control plane traffic from external networks.
SC-07(05) Deny by Default — Allow by Exception ModerateHigh
Deny network communications traffic by default and allow network communications traffic by exception [Selection (one or more): at managed interfaces; for [Assignment: organization-defined systems]].
SC-07(07) Split Tunneling for Remote Devices ModerateHigh
Prevent split tunneling for remote devices connecting to organizational systems unless the split tunnel is securely provisioned using [Assignment: organization-defined safeguards].
SC-07(08) Route Traffic to Authenticated Proxy Servers ModerateHigh
Route [Assignment: organization-defined internal communications traffic] to [Assignment: organization-defined external networks] through authenticated proxy servers at managed interfaces.
SC-07(09) Restrict Threatening Outgoing Communications Traffic
a. Detect and deny outgoing communications traffic posing a threat to external systems; and b. Audit the identity of internal users associated with denied communications.
SC-07(10) Prevent Exfiltration
a. Prevent the exfiltration of information; and b. Conduct exfiltration tests [Assignment: organization-defined frequency].
SC-07(11) Restrict Incoming Communications Traffic
Only allow incoming communications from [Assignment: organization-defined authorized sources] to be routed to [Assignment: organization-defined authorized destinations].
SC-07(12) Host-based Protection
Implement [Assignment: organization-defined host-based boundary protection mechanisms] at [Assignment: organization-defined system components].
SC-07(13) Isolation of Security Tools, Mechanisms, and Support Components
Isolate [Assignment: organization-defined information security tools, mechanisms, and support components] from other internal system components by implementing physically separate subnetworks with managed interfaces to other components of the system.
SC-07(14) Protect Against Unauthorized Physical Connections
Protect against unauthorized physical connections at [Assignment: organization-defined managed interfaces].
SC-07(15) Networked Privileged Accesses
Route networked, privileged accesses through a dedicated, managed interface for purposes of access control and auditing.
SC-07(16) Prevent Discovery of System Components
Prevent the discovery of specific system components that represent a managed interface.
SC-07(17) Automated Enforcement of Protocol Formats
Enforce adherence to protocol formats.
SC-07(18) Fail Secure High
Prevent systems from entering unsecure states in the event of an operational failure of a boundary protection device.
SC-07(19) Block Communication from Non-organizationally Configured Hosts
Block inbound and outbound communications traffic between [Assignment: organization-defined communication clients] that are independently configured by end users and external service providers.
SC-07(20) Dynamic Isolation and Segregation
Provide the capability to dynamically isolate [Assignment: organization-defined system components] from other system components.
SC-07(21) Isolation of System Components High
Employ boundary protection mechanisms to isolate [Assignment: organization-defined system components] supporting [Assignment: organization-defined missions and/or business functions].
SC-07(22) Separate Subnets for Connecting to Different Security Domains
Implement separate network addresses to connect to systems in different security domains.
SC-07(23) Disable Sender Feedback on Protocol Validation Failure
Disable feedback to senders on protocol format validation failure.
SC-07(24) Personally Identifiable Information Privacy
For systems that process personally identifiable information: a. Apply the following processing rules to data elements of personally identifiable information: [Assignment: organization-defined processing rules]; b. Monitor for permitted processing at the external interfaces to the system and at key internal boundaries within the system; c. Document each processing exception; and d. Review and remove exceptions that are no longer supported.
SC-07(25) Unclassified National Security System Connections
Prohibit the direct connection of [Assignment: organization-defined unclassified national security system] to an external network without the use of [Assignment: organization-defined boundary protection device].
SC-07(26) Classified National Security System Connections
Prohibit the direct connection of a classified national security system to an external network without the use of [Assignment: organization-defined boundary protection device].
SC-07(27) Unclassified Non-national Security System Connections
Prohibit the direct connection of [Assignment: organization-defined unclassified non-national security system] to an external network without the use of [Assignment: organization-defined boundary protection device].
SC-07(28) Connections to Public Networks
Prohibit the direct connection of [Assignment: organization-defined system] to a public network.
SC-07(29) Separate Subnets to Isolate Functions
Implement [Selection (one): physically; logically] separate subnetworks to isolate the following critical system components and functions: [Assignment: organization-defined critical system components and functions].
Patterns that use this control (29)
Grouped by the emphasis each pattern gives it.
Critical (12)
- SP-015 Secure Remote Working
- SP-017 Secure Network Zone Module
- SP-019 Secure Ad-Hoc File Exchange Pattern
- SP-023 Industrial Control Systems
- SP-026 PCI Full Environment
- SP-027 Secure LLM Usage
- SP-029 Zero Trust Architecture
- SP-030 API Security
- SP-034 Cyber Resilience
- SP-047 Secure Agentic AI Frameworks
- SP-051 Tokenised Asset Security Architecture (draft)
- SP-054 CBDC and Digital Currency Infrastructure (draft)
Important (13)
- SP-011 Cloud Computing Pattern
- SP-013 Data Security Pattern
- SP-020 Email Transport Layer Security (TLS) Pattern
- SP-025 Advanced Monitoring and Detection
- SP-028 Secure DevOps Pipeline Pattern
- SP-031 Security Monitoring and Response
- SP-035 Offensive Security Testing
- SP-036 Incident Response
- SP-037 Privileged User Management
- SP-038 Vulnerability Management and Patching
- SP-042 Third Party Risk Management
- SP-046 External Attack Surface Management
- SP-053 Zero-Knowledge Proof Architecture (draft)
MITRE ATT&CK Techniques (156)
ATT&CK v16.1Techniques mitigated by this control, mapped via CTID.