Skip to content

System and Communications Protection (SC)

This page contains all 139 controls and control enhancements in the System and Communications Protection (SC) family from the vendored NIST SP 800-53 Revision 5 OSCAL catalog.

Official NIST OSCAL source

  • Catalog version: 5.2.0
  • OSCAL version: 1.2.2
  • Catalog last modified: May 11, 2026

SC-01 (Policy and Procedures)

FedRAMP Rev5 Baselines: Class BClass CClass D
  • a. Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]:
    • 1. [Selection: one or more of: organization-level; mission/business-process-level; system-level] system and communications protection policy that:
      • (a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
      • (b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and
    • 2. Procedures to facilitate the implementation of the system and communications protection policy and the associated system and communications protection controls;
  • b. Designate an [Assignment: organization-defined official] to manage the development, documentation, and dissemination of the system and communications protection policy and procedures; and
  • c. Review and update the current system and communications protection:
    • 1. Policy [Assignment: organization-defined frequency] and following [Assignment: organization-defined events]; and
    • 2. Procedures [Assignment: organization-defined frequency] and following [Assignment: organization-defined events].

This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-02 (Separation of System and User Functionality)

FedRAMP Rev5 Baselines: Class CClass D

Separate user functionality, including user interface services, from system management functionality.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-02 (01) (Interfaces for Non-privileged Users)

Prevent the presentation of system management functionality at interfaces to non-privileged users.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-02 (02) (Disassociability)

Store state information from applications and software separately.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-03 (Security Function Isolation)

FedRAMP Rev5 Baselines: Class D

Isolate security functions from nonsecurity functions.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-03 (01) (Hardware Separation)

Employ hardware separation mechanisms to implement security function isolation.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-03 (02) (Access and Flow Control Functions)

Isolate security functions enforcing access and information flow control from nonsecurity functions and from other security functions.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-03 (03) (Minimize Nonsecurity Functionality)

Minimize the number of nonsecurity functions included within the isolation boundary containing security functions.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-03 (04) (Module Coupling and Cohesiveness)

Implement security functions as largely independent modules that maximize internal cohesiveness within modules and minimize coupling between modules.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-03 (05) (Layered Structures)

Implement security functions as a layered structure minimizing interactions between layers of the design and avoiding any dependence by lower layers on the functionality or correctness of higher layers.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-04 (Information in Shared System Resources)

FedRAMP Rev5 Baselines: Class CClass D

Prevent unauthorized and unintended information transfer via shared system resources.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-04 (02) (Multilevel or Periods Processing)

Prevent unauthorized information transfer via shared resources in accordance with [Assignment: organization-defined procedures] when system processing explicitly switches between different information classification levels or security categories.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-05 (Denial-of-service Protection)

FedRAMP Rev5 Baselines: Class BClass CClass D
  • a. [Selection: one of: protect against; limit] the effects of the following types of denial-of-service events: [Assignment: organization-defined types of denial-of-service events]; and
  • b. Employ the following controls to achieve the denial-of-service objective: [Assignment: organization-defined controls by type of denial-of-service event].

This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-05 (01) (Restrict Ability to Attack Other Systems)

Restrict the ability of individuals to launch the following denial-of-service attacks against other systems: [Assignment: organization-defined denial-of-service attacks].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-05 (02) (Capacity, Bandwidth, and Redundancy)

Manage capacity, bandwidth, or other redundancy to limit the effects of information flooding denial-of-service attacks.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-05 (03) (Detection and Monitoring)

  • (a) Employ the following monitoring tools to detect indicators of denial-of-service attacks against, or launched from, the system: [Assignment: organization-defined monitoring tools]; and
  • (b) Monitor the following system resources to determine if sufficient resources exist to prevent effective denial-of-service attacks: [Assignment: organization-defined system resources].

This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-06 (Resource Availability)

Protect the availability of resources by allocating [Assignment: organization-defined resources] by [Selection: one or more of: priority; quota].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-07 (Boundary Protection)

FedRAMP Rev5 Baselines: Class BClass CClass D
  • a. Monitor and control communications at the external managed interfaces to the system and at key internal managed interfaces within the system;
  • b. Implement subnetworks for publicly accessible system components that are [Selection: one of: physically; logically] separated from internal organizational networks; and
  • c. Connect to external networks or systems only through managed interfaces consisting of boundary protection devices arranged in accordance with an organizational security and privacy architecture.

FedRAMP Guidance

SC-7 (b) may be met by using any technical capability or complement of capabilities that ensures logical separation between publicly accessible components and internal networks by preventing traversal without inspection and authorization; traffic may not flow unrestricted from publicly accessible components to internal networks.


External Link for Additional Information: myctrl.tools


SC-07 (03) (Access Points)

FedRAMP Rev5 Baselines: Class CClass D

Limit the number of external network connections to the system.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-07 (04) (External Telecommunications Services)

FedRAMP Rev5 Baselines: Class CClass D
  • (a) Implement a managed interface for each external telecommunication service;
  • (b) Establish a traffic flow policy for each managed interface;
  • (c) Protect the confidentiality and integrity of the information being transmitted across each interface;
  • (d) Document each exception to the traffic flow policy with a supporting mission or business need and duration of that need;
  • (e) Review exceptions to the traffic flow policy [Assignment: organization-defined frequency] and remove exceptions that are no longer supported by an explicit mission or business need;
  • (f) Prevent unauthorized exchange of control plane traffic with external networks;
  • (g) Publish information to enable remote networks to detect unauthorized control plane traffic from internal networks; and
  • (h) Filter unauthorized control plane traffic from external networks.

This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-07 (05) (Deny by Default — Allow by Exception)

FedRAMP Rev5 Baselines: Class CClass D

Deny network communications traffic by default and allow network communications traffic by exception [Selection: one or more of: at managed interfaces; for].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-07 (07) (Split Tunneling for Remote Devices)

FedRAMP Rev5 Baselines: Class CClass D

Prevent split tunneling for remote devices connecting to organizational systems unless the split tunnel is securely provisioned using [Assignment: organization-defined safeguards].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-07 (08) (Route Traffic to Authenticated Proxy Servers)

FedRAMP Rev5 Baselines: Class CClass D

Route [Assignment: organization-defined internal communications traffic] to [Assignment: organization-defined external networks] through authenticated proxy servers at managed interfaces.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-07 (09) (Restrict Threatening Outgoing Communications Traffic)

  • (a) Detect and deny outgoing communications traffic posing a threat to external systems; and
  • (b) Audit the identity of internal users associated with denied communications.

This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-07 (10) (Prevent Exfiltration)

FedRAMP Rev5 Baselines: Class D
  • (a) Prevent the exfiltration of information; and
  • (b) Conduct exfiltration tests [Assignment: organization-defined frequency].

This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-07 (11) (Restrict Incoming Communications Traffic)

Only allow incoming communications from [Assignment: organization-defined authorized sources] to be routed to [Assignment: organization-defined authorized destinations].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-07 (12) (Host-based Protection)

FedRAMP Rev5 Baselines: Class CClass D

Implement [Assignment: organization-defined host-based boundary protection mechanisms] at [Assignment: organization-defined system components].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-07 (13) (Isolation of Security Tools, Mechanisms, and Support Components)

Isolate [Assignment: organization-defined information security tools, mechanisms, and support components] from other internal system components by implementing physically separate subnetworks with managed interfaces to other components of the system.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-07 (14) (Protect Against Unauthorized Physical Connections)

Protect against unauthorized physical connections at [Assignment: organization-defined managed interfaces].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-07 (15) (Networked Privileged Accesses)

Route networked, privileged accesses through a dedicated, managed interface for purposes of access control and auditing.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-07 (16) (Prevent Discovery of System Components)

Prevent the discovery of specific system components that represent a managed interface.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-07 (17) (Automated Enforcement of Protocol Formats)

Enforce adherence to protocol formats.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-07 (18) (Fail Secure)

FedRAMP Rev5 Baselines: Class CClass D

Prevent systems from entering unsecure states in the event of an operational failure of a boundary protection device.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-07 (19) (Block Communication from Non-organizationally Configured Hosts)

Block inbound and outbound communications traffic between [Assignment: organization-defined communication clients] that are independently configured by end users and external service providers.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-07 (20) (Dynamic Isolation and Segregation)

FedRAMP Rev5 Baselines: Class D

Provide the capability to dynamically isolate [Assignment: organization-defined system components] from other system components.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-07 (21) (Isolation of System Components)

FedRAMP Rev5 Baselines: Class D

Employ boundary protection mechanisms to isolate [Assignment: organization-defined system components] supporting [Assignment: organization-defined missions and/or business functions].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-07 (22) (Separate Subnets for Connecting to Different Security Domains)

Implement separate network addresses to connect to systems in different security domains.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-07 (23) (Disable Sender Feedback on Protocol Validation Failure)

Disable feedback to senders on protocol format validation failure.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-07 (24) (Personally Identifiable Information)

For systems that process personally identifiable information:

  • (a) Apply the following processing rules to data elements of personally identifiable information: [Assignment: organization-defined processing rules];
  • (b) Monitor for permitted processing at the external interfaces to the system and at key internal boundaries within the system;
  • (c) Document each processing exception; and
  • (d) Review and remove exceptions that are no longer supported.

This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-07 (25) (Unclassified National Security System Connections)

Prohibit the direct connection of [Assignment: organization-defined unclassified national security system] to an external network without the use of [Assignment: organization-defined boundary protection device].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-07 (26) (Classified National Security System Connections)

Prohibit the direct connection of a classified national security system to an external network without the use of [Assignment: organization-defined boundary protection device].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-07 (27) (Unclassified Non-national Security System Connections)

Prohibit the direct connection of [Assignment: organization-defined unclassified, non-national security system] to an external network without the use of [Assignment: organization-defined boundary protection device].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-07 (28) (Connections to Public Networks)

Prohibit the direct connection of [Assignment: organization-defined system] to a public network.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-07 (29) (Separate Subnets to Isolate Functions)

Implement [Selection: one of: physically; logically] separate subnetworks to isolate the following critical system components and functions: [Assignment: organization-defined critical system components and functions].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-08 (Transmission Confidentiality and Integrity)

FedRAMP Rev5 Baselines: Class BClass CClass D

Protect the [Selection: one or more of: confidentiality; integrity] of transmitted information.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-08 (01) (Cryptographic Protection)

FedRAMP Rev5 Baselines: Class BClass CClass D

Implement cryptographic mechanisms to [Selection: one or more of: prevent unauthorized disclosure of information; detect changes to information] during transmission.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-08 (02) (Pre- and Post-transmission Handling)

Maintain the [Selection: one or more of: confidentiality; integrity] of information during preparation for transmission and during reception.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-08 (03) (Cryptographic Protection for Message Externals)

Implement cryptographic mechanisms to protect message externals unless otherwise protected by [Assignment: organization-defined alternative physical controls].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-08 (04) (Conceal or Randomize Communications)

Implement cryptographic mechanisms to conceal or randomize communication patterns unless otherwise protected by [Assignment: organization-defined alternative physical controls].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-08 (05) (Protected Distribution System)

Implement [Assignment: organization-defined protected distribution system] to [Selection: one or more of: prevent unauthorized disclosure of information; detect changes to information] during transmission.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-10 (Network Disconnect)

FedRAMP Rev5 Baselines: Class CClass D

Terminate the network connection associated with a communications session at the end of the session or after [Assignment: organization-defined time period] of inactivity.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-11 (Trusted Path)

  • a. Provide a [Selection: one of: physically; logically] isolated trusted communications path for communications between the user and the trusted components of the system; and
  • b. Permit users to invoke the trusted communications path for communications between the user and the following security functions of the system, including at a minimum, authentication and re-authentication: [Assignment: organization-defined security functions].

This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-11 (01) (Irrefutable Communications Path)

  • (a) Provide a trusted communications path that is irrefutably distinguishable from other communications paths; and
  • (b) Initiate the trusted communications path for communications between the [Assignment: organization-defined security functions] of the system and the user.

This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-12 (Cryptographic Key Establishment and Management)

FedRAMP Rev5 Baselines: Class BClass CClass D

Establish and manage cryptographic keys when cryptography is employed within the system in accordance with the following key management requirements: [Assignment: organization-defined requirements].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-12 (01) (Availability)

FedRAMP Rev5 Baselines: Class D

Maintain availability of information in the event of the loss of cryptographic keys by users.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-12 (02) (Symmetric Keys)

Produce, control, and distribute symmetric cryptographic keys using [Selection: one of: NIST FIPS-validated; NSA-approved] key management technology and processes.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-12 (03) (Asymmetric Keys)

Produce, control, and distribute asymmetric cryptographic keys using [Selection: one of: NSA-approved key management technology and processes; prepositioned keying material; DoD-approved or DoD-issued Medium Assurance PKI certificates; DoD-approved or DoD-issued Medium Hardware Assurance PKI certificates and hardware security tokens that protect the user’s private key; certificates issued in accordance with organization-defined requirements].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-12 (06) (Physical Control of Keys)

Maintain physical control of cryptographic keys when stored information is encrypted by external service providers.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-13 (Cryptographic Protection)

FedRAMP Rev5 Baselines: Class BClass CClass D
  • a. Determine the [Assignment: organization-defined cryptographic uses]; and
  • b. Implement the following types of cryptography required for each specified cryptographic use: [Assignment: organization-defined types of cryptography].

FedRAMP Guidance

Follow the FedRAMP Cryptographic Module Use rules.


External Link for Additional Information: myctrl.tools


SC-15 (Collaborative Computing Devices and Applications)

FedRAMP Rev5 Baselines: Class BClass CClass D
  • a. Prohibit remote activation of collaborative computing devices and applications with the following exceptions: [Assignment: organization-defined exceptions where remote activation is to be allowed]; and
  • b. Provide an explicit indication of use to users physically present at the devices.

This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-15 (01) (Physical or Logical Disconnect)

Provide [Selection: one or more of: physical; logical] disconnect of collaborative computing devices in a manner that supports ease of use.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-15 (03) (Disabling and Removal in Secure Work Areas)

Disable or remove collaborative computing devices and applications from [Assignment: organization-defined systems or system components] in [Assignment: organization-defined secure work areas].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-15 (04) (Explicitly Indicate Current Participants)

Provide an explicit indication of current participants in [Assignment: organization-defined online meetings and teleconferences].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-16 (Transmission of Security and Privacy Attributes)

Associate [Assignment: organization-defined security and privacy attributes] with information exchanged between systems and between system components.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-16 (01) (Integrity Verification)

Verify the integrity of transmitted security and privacy attributes.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-16 (02) (Anti-spoofing Mechanisms)

Implement anti-spoofing mechanisms to prevent adversaries from falsifying the security attributes indicating the successful application of the security process.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-16 (03) (Cryptographic Binding)

Implement [Assignment: organization-defined mechanisms or techniques] to bind security and privacy attributes to transmitted information.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-17 (Public Key Infrastructure Certificates)

FedRAMP Rev5 Baselines: Class CClass D
  • a. Issue public key certificates under an [Assignment: organization-defined certificate policy] or obtain public key certificates from an approved service provider; and
  • b. Include only approved trust anchors in trust stores or certificate stores managed by the organization.

This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-18 (Mobile Code)

FedRAMP Rev5 Baselines: Class CClass D
  • a. Define acceptable and unacceptable mobile code and mobile code technologies; and
  • b. Authorize, monitor, and control the use of mobile code within the system.

This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-18 (01) (Identify Unacceptable Code and Take Corrective Actions)

Identify [Assignment: organization-defined unacceptable mobile code] and take [Assignment: organization-defined corrective actions].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-18 (02) (Acquisition, Development, and Use)

Verify that the acquisition, development, and use of mobile code to be deployed in the system meets [Assignment: organization-defined mobile code requirements].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-18 (03) (Prevent Downloading and Execution)

Prevent the download and execution of [Assignment: organization-defined unacceptable mobile code].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-18 (04) (Prevent Automatic Execution)

Prevent the automatic execution of mobile code in [Assignment: organization-defined software applications] and enforce [Assignment: organization-defined actions] prior to executing the code.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-18 (05) (Allow Execution Only in Confined Environments)

Allow execution of permitted mobile code only in confined virtual machine environments.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-20 (Secure Name/Address Resolution Service (Authoritative Source))

FedRAMP Rev5 Baselines: Class BClass CClass D
  • a. Provide additional data origin authentication and integrity verification artifacts along with the authoritative name resolution data the system returns in response to external name/address resolution queries; and
  • b. Provide the means to indicate the security status of child zones and (if the child supports secure resolution services) to enable verification of a chain of trust among parent and child domains, when operating as part of a distributed, hierarchical namespace.

This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-20 (02) (Data Origin and Integrity)

Provide data origin and integrity protection artifacts for internal name/address resolution queries.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-21 (Secure Name/Address Resolution Service (Recursive or Caching Resolver))

FedRAMP Rev5 Baselines: Class BClass CClass D

Request and perform data origin authentication and data integrity verification on the name/address resolution responses the system receives from authoritative sources.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-22 (Architecture and Provisioning for Name/Address Resolution Service)

FedRAMP Rev5 Baselines: Class BClass CClass D

Ensure the systems that collectively provide name/address resolution service for an organization are fault-tolerant and implement internal and external role separation.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-23 (Session Authenticity)

FedRAMP Rev5 Baselines: Class CClass D

Protect the authenticity of communications sessions.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-23 (01) (Invalidate Session Identifiers at Logout)

Invalidate session identifiers upon user logout or other session termination.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-23 (03) (Unique System-generated Session Identifiers)

Generate a unique session identifier for each session with [Assignment: organization-defined randomness requirements] and recognize only session identifiers that are system-generated.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-23 (05) (Allowed Certificate Authorities)

Only allow the use of [Assignment: organization-defined certificated authorities] for verification of the establishment of protected sessions.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-24 (Fail in Known State)

FedRAMP Rev5 Baselines: Class D

Fail to a [Assignment: organization-defined known system state] for the following failures on the indicated components while preserving [Assignment: organization-defined system state information] in failure: [Assignment: organization-defined types of system failures on system components].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-25 (Thin Nodes)

Employ minimal functionality and information storage on the following system components: [Assignment: organization-defined system components].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-26 (Decoys)

Include components within organizational systems specifically designed to be the target of malicious attacks for detecting, deflecting, and analyzing such attacks.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-27 (Platform-independent Applications)

Include within organizational systems the following platform independent applications: [Assignment: organization-defined platform-independent applications].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-28 (Protection of Information at Rest)

FedRAMP Rev5 Baselines: Class BClass CClass D

Protect the [Selection: one or more of: confidentiality; integrity] of the following information at rest: [Assignment: organization-defined information at rest].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-28 (01) (Cryptographic Protection)

FedRAMP Rev5 Baselines: Class BClass CClass D

Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of the following information at rest on [Assignment: organization-defined system components or media]: [Assignment: organization-defined information].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-28 (02) (Offline Storage)

Remove the following information from online storage and store offline in a secure location: [Assignment: organization-defined information].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-28 (03) (Cryptographic Keys)

Provide protected storage for cryptographic keys [Selection: one of: hardware-protected key store].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-29 (Heterogeneity)

Employ a diverse set of information technologies for the following system components in the implementation of the system: [Assignment: organization-defined system components].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-29 (01) (Virtualization Techniques)

Employ virtualization techniques to support the deployment of a diversity of operating systems and applications that are changed [Assignment: organization-defined frequency].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-30 (Concealment and Misdirection)

Employ the following concealment and misdirection techniques for [Assignment: organization-defined systems] at [Assignment: organization-defined time periods] to confuse and mislead adversaries: [Assignment: organization-defined concealment and misdirection techniques].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-30 (02) (Randomness)

Employ [Assignment: organization-defined techniques] to introduce randomness into organizational operations and assets.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-30 (03) (Change Processing and Storage Locations)

Change the location of [Assignment: organization-defined processing and/or storage] [Selection: one of: random time intervals]].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-30 (04) (Misleading Information)

Employ realistic, but misleading information in [Assignment: organization-defined system components] about its security state or posture.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-30 (05) (Concealment of System Components)

Employ the following techniques to hide or conceal [Assignment: organization-defined system components]: [Assignment: organization-defined techniques].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-31 (Covert Channel Analysis)

  • a. Perform a covert channel analysis to identify those aspects of communications within the system that are potential avenues for covert [Selection: one or more of: storage; timing] channels; and
  • b. Estimate the maximum bandwidth of those channels.

This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-31 (01) (Test Covert Channels for Exploitability)

Test a subset of the identified covert channels to determine the channels that are exploitable.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-31 (02) (Maximum Bandwidth)

Reduce the maximum bandwidth for identified covert [Selection: one or more of: storage; timing] channels to [Assignment: organization-defined values].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-31 (03) (Measure Bandwidth in Operational Environments)

Measure the bandwidth of [Assignment: organization-defined subset of identified covert channels] in the operational environment of the system.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-32 (System Partitioning)

Partition the system into [Assignment: organization-defined system components] residing in separate [Selection: one of: physical; logical] domains or environments based on [Assignment: organization-defined circumstances for the physical or logical separation of components].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-32 (01) (Separate Physical Domains for Privileged Functions)

Partition privileged functions into separate physical domains.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-34 (Non-modifiable Executable Programs)

For [Assignment: organization-defined system components], load and execute:

  • a. The operating environment from hardware-enforced, read-only media; and
  • b. The following applications from hardware-enforced, read-only media: [Assignment: organization-defined applications].

This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-34 (01) (No Writable Storage)

Employ [Assignment: organization-defined system components] with no writeable storage that is persistent across component restart or power on/off.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-34 (02) (Integrity Protection on Read-only Media)

Protect the integrity of information prior to storage on read-only media and control the media after such information has been recorded onto the media.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-35 (External Malicious Code Identification)

Include system components that proactively seek to identify network-based malicious code or malicious websites.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-36 (Distributed Processing and Storage)

Distribute the following processing and storage components across multiple [Selection: one of: physical locations; logical domains]: [Assignment: organization-defined processing and storage components].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-36 (01) (Polling Techniques)

  • (a) Employ polling techniques to identify potential faults, errors, or compromises to the following processing and storage components: [Assignment: organization-defined distributed processing and storage components]; and
  • (b) Take the following actions in response to identified faults, errors, or compromises: [Assignment: organization-defined actions].

This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-36 (02) (Synchronization)

Synchronize the following duplicate systems or system components: [Assignment: organization-defined duplicate systems or system components].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-37 (Out-of-band Channels)

Employ the following out-of-band channels for the physical delivery or electronic transmission of [Assignment: organization-defined information, system components, or devices] to [Assignment: organization-defined individuals or systems]: [Assignment: organization-defined out-of-band channels].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-37 (01) (Ensure Delivery and Transmission)

Employ [Assignment: organization-defined controls] to ensure that only [Assignment: organization-defined individuals or systems] receive the following information, system components, or devices: [Assignment: organization-defined information, system components, or devices].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-38 (Operations Security)

Employ the following operations security controls to protect key organizational information throughout the system development life cycle: [Assignment: organization-defined operations security controls].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-39 (Process Isolation)

FedRAMP Rev5 Baselines: Class BClass CClass D

Maintain a separate execution domain for each executing system process.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-39 (01) (Hardware Separation)

Implement hardware separation mechanisms to facilitate process isolation.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-39 (02) (Separate Execution Domain Per Thread)

Maintain a separate execution domain for each thread in [Assignment: organization-defined multi-threaded processing].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-40 (Wireless Link Protection)

Protect external and internal [Assignment: organization-defined wireless links] from the following signal parameter attacks: [Assignment: organization-defined types of signal parameter attacks or references to sources for such attacks].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-40 (01) (Electromagnetic Interference)

Implement cryptographic mechanisms that achieve [Assignment: organization-defined level of protection] against the effects of intentional electromagnetic interference.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-40 (02) (Reduce Detection Potential)

Implement cryptographic mechanisms to reduce the detection potential of wireless links to [Assignment: organization-defined level of reduction].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-40 (03) (Imitative or Manipulative Communications Deception)

Implement cryptographic mechanisms to identify and reject wireless transmissions that are deliberate attempts to achieve imitative or manipulative communications deception based on signal parameters.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-40 (04) (Signal Parameter Identification)

Implement cryptographic mechanisms to prevent the identification of [Assignment: organization-defined wireless transmitters] by using the transmitter signal parameters.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-41 (Port and I/O Device Access)

[Selection: one of: physically; logically] disable or remove [Assignment: organization-defined connection ports or input/output devices] on the following systems or system components: [Assignment: organization-defined systems or system components].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-42 (Sensor Capability and Data)

  • a. Prohibit [Selection: one or more of: the use of devices possessing in; the remote activation of environmental sensing capabilities on organizational systems or system components with the following exceptions:]; and
  • b. Provide an explicit indication of sensor use to [Assignment: organization-defined group of users].

This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-42 (01) (Reporting to Authorized Individuals or Roles)

Verify that the system is configured so that data or information collected by the [Assignment: organization-defined sensors] is only reported to authorized individuals or roles.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-42 (02) (Authorized Use)

Employ the following measures so that data or information collected by [Assignment: organization-defined sensors] is only used for authorized purposes: [Assignment: organization-defined measures].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-42 (04) (Notice of Collection)

Employ the following measures to facilitate an individual’s awareness that personally identifiable information is being collected by [Assignment: organization-defined sensors]: [Assignment: organization-defined measures].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-42 (05) (Collection Minimization)

Employ [Assignment: organization-defined sensors] that are configured to minimize the collection of information about individuals that is not needed.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-43 (Usage Restrictions)

  • a. Establish usage restrictions and implementation guidelines for the following system components: [Assignment: organization-defined components]; and
  • b. Authorize, monitor, and control the use of such components within the system.

This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-44 (Detonation Chambers)

Employ a detonation chamber capability within [Assignment: organization-defined system, system component, or location].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-45 (System Time Synchronization)

FedRAMP Rev5 Baselines: Class CClass D

Synchronize system clocks within and between systems and system components.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-45 (01) (Synchronization with Authoritative Time Source)

FedRAMP Rev5 Baselines: Class CClass D
  • (a) Compare the internal system clocks [Assignment: organization-defined frequency] with [Assignment: organization-defined authoritative time source]; and
  • (b) Synchronize the internal system clocks to the authoritative time source when the time difference is greater than [Assignment: organization-defined time period].

This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-45 (02) (Secondary Authoritative Time Source)

  • (a) Identify a secondary authoritative time source that is in a different geographic region than the primary authoritative time source; and
  • (b) Synchronize the internal system clocks to the secondary authoritative time source if the primary authoritative time source is unavailable.

This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-46 (Cross Domain Policy Enforcement)

Implement a policy enforcement mechanism [Selection: one of: physically; logically] between the physical and/or network interfaces for the connecting security domains.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-47 (Alternate Communications Paths)

Establish [Assignment: organization-defined alternate communication paths] for system operations organizational command and control.


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-48 (Sensor Relocation)

Relocate [Assignment: organization-defined sensors and monitoring capabilities] to [Assignment: organization-defined locations] under the following conditions or circumstances: [Assignment: organization-defined conditions or circumstances].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-48 (01) (Dynamic Relocation of Sensors or Monitoring Capabilities)

Dynamically relocate [Assignment: organization-defined sensors and monitoring capabilities] to [Assignment: organization-defined locations] under the following conditions or circumstances: [Assignment: organization-defined conditions or circumstances].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-49 (Hardware-enforced Separation and Policy Enforcement)

Implement hardware-enforced separation and policy enforcement mechanisms between [Assignment: organization-defined security domains].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-50 (Software-enforced Separation and Policy Enforcement)

Implement software-enforced separation and policy enforcement mechanisms between [Assignment: organization-defined security domains].


This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


SC-51 (Hardware-based Protection)

  • a. Employ hardware-based, write-protect for [Assignment: organization-defined system firmware components]; and
  • b. Implement specific procedures for [Assignment: organization-defined authorized individuals] to manually disable hardware write-protect for firmware modifications and re-enable the write-protect prior to returning to operational mode.

This control does not have additional FedRAMP guidance or FedRAMP-assigned parameter values.


External Link for Additional Information: myctrl.tools


Comments