← Controls / SC

SC-18 Mobile Code

System and Communications Protection

Moderate High

Description

a. Define acceptable and unacceptable mobile code and mobile code technologies; and b. Authorize, monitor, and control the use of mobile code within the system.

Supplemental Guidance

Mobile code includes any program, application, or content that can be transmitted across a network (e.g., embedded in an email, document, or website) and executed on a remote system. Decisions regarding the use of mobile code within organizational systems are based on the potential for the code to cause damage to the systems if used maliciously. Mobile code technologies include Java applets, JavaScript, HTML5, WebGL, and VBScript. Usage restrictions and implementation guidelines apply to both the selection and use of mobile code installed on servers and mobile code downloaded and executed on individual workstations and devices, including notebook computers and smart phones. Mobile code policy and procedures address specific actions taken to prevent the development, acquisition, and introduction of unacceptable mobile code within organizational systems, including requiring mobile code to be digitally signed by a trusted source.

Changes from Rev 4

Control text replaces requirement to establish usage restrictions and implementation guidance with requirement to authorize, monitor, and control the use of mobile code within the system Discussion expanded with additional examples of mobile code and factors that should be included in mobile code policy and procedures

Enhancements (5)

What NIST adds to this control. Select one to read its statement.

SC-18(01) Identify Unacceptable Code and Take Corrective Actions

Identify [Assignment: organization-defined unacceptable mobile code] and take [Assignment: organization-defined corrective actions].

SC-18(02) Acquisition, Development, and Use

Verify that the acquisition, development, and use of mobile code to be deployed in the system meets [Assignment: organization-defined mobile code requirements].

SC-18(03) Prevent Downloading and Execution

Prevent the download and execution of [Assignment: organization-defined unacceptable mobile code].

SC-18(04) Prevent Automatic Execution

Prevent the automatic execution of mobile code in [Assignment: organization-defined software applications] and enforce [Assignment: organization-defined actions] prior to executing the code.

SC-18(05) Allow Execution Only in Confined Environments

Allow execution of permitted mobile code only in confined virtual machine environments.

Patterns that use this control (3)

Grouped by the emphasis each pattern gives it.

MITRE ATT&CK Techniques (38)

ATT&CK v16.1

Techniques mitigated by this control, mapped via CTID.

Initial Access 2 Execution 7 Persistence 7 Privilege Escalation 15 Defense Evasion 18 Credential Access 1 Lateral Movement 2
Show all 38 techniques grouped by tactic

Compliance Mappings

CIS Controls v8

CIS 9CIS 9.6

IEC 62443

3-3 SR 2.4

ASD Essential Eight

E8-3E8-3 ML2E8-4E8-4 ML1

BSI IT-Grundschutz

APP.1.1

ANSSI

Hygiene.20Hygiene.22SecNumCloud.13.1

FINMA Circular 2023/1

IV.B.d(59)IV.C(64)

OSFI B-13

B-13.3.2

EU GDPR

Art.32(1)(b)

EU DORA

Art.9(4)(e)

RBI CSF

Annex1.2

FISC Security Guidelines

FISC.T8

HKMA TM-E-1

TME1.10.2

DNB Good Practice

DNB.19.1

NCA ECC

2-3

FFIEC IS

II.C.12

SEBI CSCRF

PR.ES

CMMC 2.0

SC

Lloyd's Minimum Standards

MS8.10

NHS DSPT

NDG-9.3NDG-9.5

OWASP MASVS v2.1

MASVS-CODE-4

ISO 17799 (legacy)

10.4.110.4.2

COBIT 4.1 (legacy)

DS5.9