# SC-15 Collaborative Computing Devices and Applications

NIST SP 800-53 control. Family: SC System and Communications Protection. Function: preventative. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: a. Prohibit remote activation of collaborative computing devices and applications with the following exceptions: [Assignment: organization-defined exceptions where remote activation is to be allowed]; and b. Provide an explicit indication of use to users physically present at the devices.
Guidance: Collaborative computing devices and applications include remote meeting devices and applications, networked white boards, cameras, and microphones. The explicit indication of use includes signals to users when collaborative computing devices and applications are activated.

## Enhancements (3)
- SC-15(01) Physical or Logical Disconnect
- SC-15(03) Disabling and Removal in Secure Work Areas
- SC-15(04) Explicitly Indicate Current Participants
Withdrawn by NIST: SC-15(02) (now in SC-07).
Each enhancement's statement: /api/v1/controls/SC-15?fields=enhancements

## Patterns that use it (1)
- Standard (1): SP-001 Client Module

## Clauses by framework (11 frameworks)
- iso_27001_2022: A.5.14
- anssi: Hygiene.22, SecNumCloud.14.1
- osfi_b13: B-13.3.2
- finma_circular: IV.B.d(59), IV.C(62)
- gdpr: Art.32(1)(b)
- dora: Art.9(4)(a)
- rbi_csf: Annex1.8
- qatar_nia: CS
- eba_ict: 3.8(a)
- hipaa_sr: §164.310(b)
- cmmc_2: SC
OSA's mapping for iso_27001_2022 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/SC-15
- Clauses only: /api/v1/controls/SC-15?fields=mappings
- Page for people: /controls/sc-15/
