# SC-18 Mobile Code

NIST SP 800-53 control. Family: SC System and Communications Protection. Function: preventative. Baselines: moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: a. Define acceptable and unacceptable mobile code and mobile code technologies; and b. Authorize, monitor, and control the use of mobile code within the system.
Guidance: Mobile code includes any program, application, or content that can be transmitted across a network (e.g., embedded in an email, document, or website) and executed on a remote system. Decisions regarding the use of mobile code within organizational systems are based on the potential for the code to cause damage to the systems if used maliciously. Mobile code technologies include Java applets, JavaScript, HTML5, WebGL, and VBScript. Usage restrictions and implementation guidelines apply to both the selection and use of mobile code installed on servers and mobile code downloaded and executed on individual workstations and devices, including notebook computers and smart phones. Mobile code policy and procedures address specific actions taken to prevent the development, acquisition, and introduction of unacceptable mobile code within organizational systems, including requiring mobile code to be digitally signed by a trusted source.

## Enhancements (5)
- SC-18(01) Identify Unacceptable Code and Take Corrective Actions
- SC-18(02) Acquisition, Development, and Use
- SC-18(03) Prevent Downloading and Execution
- SC-18(04) Prevent Automatic Execution
- SC-18(05) Allow Execution Only in Confined Environments
Each enhancement's statement: /api/v1/controls/SC-18?fields=enhancements

## Patterns that use it (3)
- Standard (3): SP-001 Client Module; SP-002 Server Module; SP-011 Cloud Computing Pattern

## Clauses by framework (20 frameworks)
- cis_controls_v8: CIS 9, CIS 9.6
- iec_62443: 3-3 SR 2.4
- asd_e8: E8-3, E8-3 ML2, E8-4, E8-4 ML1
- bsi_grundschutz: APP.1.1
- anssi: Hygiene.20, Hygiene.22, SecNumCloud.13.1
- osfi_b13: B-13.3.2
- finma_circular: IV.B.d(59), IV.C(64)
- gdpr: Art.32(1)(b)
- dora: Art.9(4)(e)
- rbi_csf: Annex1.2
- fisc: FISC.T8
- hkma_tme1: TME1.10.2
- dnb_good_practice: DNB.19.1
- nca_ecc: 2-3
- ffiec_is: II.C.12
- sebi_cscrf: PR.ES
- cmmc_2: SC
- lloyds_ms: MS8.10
- nhs_dspt: NDG-9.3, NDG-9.5
- owasp_masvs_v2: MASVS-CODE-4

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/SC-18
- Clauses only: /api/v1/controls/SC-18?fields=mappings
- Page for people: /controls/sc-18/
