SC
System and Communications Protection
Monitors, controls, and protects communications at external boundaries and key internal boundaries of organizational systems.
Family stats
Controls
16
Objectives
41
L1
2
L2 only
14
16 controls in this family
All
Level 1
Level 2 only
3.13.1
Monitor, control, and protect communications (i.e., information transmitted or received by...
L1
›
3.13.10
Establish and manage cryptographic keys for cryptography employed in organizational systems.
L2
›
3.13.11
Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.
L2
›
3.13.12
L2
›
3.13.13
Control and monitor the use of mobile code.
L2
›
3.13.14
Control and monitor the use of Voice over Internet Protocol (VoIP) technologies
L2
›
3.13.15
Protect the authenticity of communications sessions
L2
›
3.13.16
Protect the confidentiality of CUI at rest.
L2
›
3.13.2
Employ architectural designs, software development techniques, and systems engineering principles...
L2
›
3.13.3
Separate user functionality from system management functionality.
L2
›
3.13.4
Prevent unauthorized and unintended information transfer via shared system resources.
L2
›
3.13.5
Implement subnetworks for publicly accessible system components that are physically or logically...
L1
›
3.13.6
Deny network communications traffic by default and allow network communications traffic by...
L2
›
3.13.7
Prevent remote devices from simultaneously establishing non-remote connections with organizational...
L2
›
3.13.8
Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission...
L2
›
3.13.9
Terminate network connections associated with communications sessions at the end of the sessions or...
L2
›
Begin the conversation
Your contract eligibility is on a clock. Let’s get to work.
A 30-minute scoping call with a senior consultant. No pitch. We listen, scope honestly, and tell you what we’d do — including whether we are the right fit.
Request a scoping call →