Browse 1,193 controls and enhancements across 20 security and privacy families. Use the GovRAMP crosswalk to locate controls referenced by Security Snapshot, Core, and Moderate.
A shared catalog supports common-control planning; designation as a common, hybrid, or system-specific control depends on your organization’s implementation and inheritance decisions.
System and Communications Protection · Enhancement
SC-7(17) · Automated Enforcement of Protocol Formats
View parent controlControl statement and discussion
NIST control statement
Enforce adherence to protocol formats.
Discussion
System components that enforce protocol formats include deep packet inspection firewalls and XML gateways. The components verify adherence to protocol formats and specifications at the application layer and identify vulnerabilities that cannot be detected by devices operating at the network or transport layers.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Enhancement
SC-7(18) · Fail Secure
View parent controlControl statement and discussion
NIST control statement
Prevent systems from entering unsecure states in the event of an operational failure of a boundary protection device.
Discussion
Fail secure is a condition achieved by employing mechanisms to ensure that in the event of operational failures of boundary protection devices at managed interfaces, systems do not enter into unsecure states where intended security properties no longer hold. Managed interfaces include routers, firewalls, and application gateways that reside on protected subnetworks (commonly referred to as demilitarized zones). Failures of boundary protection devices cannot lead to or cause information external to the devices to enter the devices nor can failures permit unauthorized information releases.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · SC-7 (18) — Direct NIST identifier reference. GovRAMP source matrix
System and Communications Protection · Enhancement
SC-7(19) · Block Communication from Non-organizationally Configured Hosts
View parent controlControl statement and discussion
NIST control statement
Block inbound and outbound communications traffic between [Assignment: communication clients] that are independently configured by end users and external service providers.
Discussion
Communication clients independently configured by end users and external service providers include instant messaging clients and video conferencing software and applications. Traffic blocking does not apply to communication clients that are configured by organizations to perform authorized functions.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Enhancement
SC-7(20) · Dynamic Isolation and Segregation
View parent controlControl statement and discussion
NIST control statement
Provide the capability to dynamically isolate [Assignment: system components] from other system components.
Discussion
The capability to dynamically isolate certain internal system components is useful when it is necessary to partition or separate system components of questionable origin from components that possess greater trustworthiness. Component isolation reduces the attack surface of organizational systems. Isolating selected system components can also limit the damage from successful attacks when such attacks occur.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Enhancement
SC-7(21) · Isolation of System Components
View parent controlControl statement and discussion
NIST control statement
Employ boundary protection mechanisms to isolate [Assignment: system components] supporting [Assignment: missions and/or business functions].
Discussion
Organizations can isolate system components that perform different mission or business functions. Such isolation limits unauthorized information flows among system components and provides the opportunity to deploy greater levels of protection for selected system components. Isolating system components with boundary protection mechanisms provides the capability for increased protection of individual system components and to more effectively control information flows between those components. Isolating system components provides enhanced protection that limits the potential harm from hostile cyber-attacks and errors. The degree of isolation varies depending upon the mechanisms chosen. Boundary protection mechanisms include routers, gateways, and firewalls that separate system components into physically separate networks or subnetworks; cross-domain devices that separate subnetworks; virtualization techniques; and the encryption of information flows among system components using distinct encryption keys.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Enhancement
SC-7(22) · Separate Subnets for Connecting to Different Security Domains
View parent controlControl statement and discussion
NIST control statement
Implement separate network addresses to connect to systems in different security domains.
Discussion
The decomposition of systems into subnetworks (i.e., subnets) helps to provide the appropriate level of protection for network connections to different security domains that contain information with different security categories or classification levels.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Enhancement
SC-7(23) · Disable Sender Feedback on Protocol Validation Failure
View parent controlControl statement and discussion
NIST control statement
Disable feedback to senders on protocol format validation failure.
Discussion
Disabling feedback to senders when there is a failure in protocol validation format prevents adversaries from obtaining information that would otherwise be unavailable.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Enhancement
SC-7(24) · Personally Identifiable Information
View parent controlControl statement and discussion
NIST control statement
For systems that process personally identifiable information:
(a) Apply the following processing rules to data elements of personally identifiable information: [Assignment: processing rules];
(b) Monitor for permitted processing at the external interfaces to the system and at key internal boundaries within the system;
(c) Document each processing exception; and
(d) Review and remove exceptions that are no longer supported.
Discussion
Managing the processing of personally identifiable information is an important aspect of protecting an individual’s privacy. Applying, monitoring for, and documenting exceptions to processing rules ensure that personally identifiable information is processed only in accordance with established privacy requirements.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Enhancement
SC-7(25) · Unclassified National Security System Connections
View parent controlControl statement and discussion
NIST control statement
Prohibit the direct connection of [Assignment: unclassified national security system] to an external network without the use of [Assignment: boundary protection device].
Discussion
A direct connection is a dedicated physical or virtual connection between two or more systems. Organizations typically do not have complete control over external networks, including the Internet. Boundary protection devices (e.g., firewalls, gateways, and routers) mediate communications and information flows between unclassified national security systems and external networks.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Enhancement
SC-7(26) · Classified National Security System Connections
View parent controlControl statement and discussion
NIST control statement
Prohibit the direct connection of a classified national security system to an external network without the use of [Assignment: boundary protection device].
Discussion
A direct connection is a dedicated physical or virtual connection between two or more systems. Organizations typically do not have complete control over external networks, including the Internet. Boundary protection devices (e.g., firewalls, gateways, and routers) mediate communications and information flows between classified national security systems and external networks. In addition, approved boundary protection devices (typically managed interface or cross-domain systems) provide information flow enforcement from systems to external networks.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Enhancement
SC-7(27) · Unclassified Non-national Security System Connections
View parent controlControl statement and discussion
NIST control statement
Prohibit the direct connection of [Assignment: unclassified, non-national security system] to an external network without the use of [Assignment: boundary protection device].
Discussion
A direct connection is a dedicated physical or virtual connection between two or more systems. Organizations typically do not have complete control over external networks, including the Internet. Boundary protection devices (e.g., firewalls, gateways, and routers) mediate communications and information flows between unclassified non-national security systems and external networks.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Enhancement
SC-7(28) · Connections to Public Networks
View parent controlControl statement and discussion
NIST control statement
Prohibit the direct connection of [Assignment: system] to a public network.
Discussion
A direct connection is a dedicated physical or virtual connection between two or more systems. A public network is a network accessible to the public, including the Internet and organizational extranets with public access.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Enhancement
SC-7(29) · Separate Subnets to Isolate Functions
View parent controlControl statement and discussion
NIST control statement
Implement [Selection (one): physically; logically] separate subnetworks to isolate the following critical system components and functions: [Assignment: critical system components and functions].
Discussion
Separating critical system components and functions from other noncritical system components and functions through separate subnetworks may be necessary to reduce susceptibility to a catastrophic or debilitating breach or compromise that results in system failure. For example, physically separating the command and control function from the in-flight entertainment function through separate subnetworks in a commercial aircraft provides an increased level of assurance in the trustworthiness of critical system functions.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Base control
SC-8 · Transmission Confidentiality and Integrity
Control statement and discussion
NIST control statement
Protect the [Selection (one-or-more): confidentiality; integrity] of transmitted information.
Discussion
Protecting the confidentiality and integrity of transmitted information applies to internal and external networks as well as any system components that can transmit information, including servers, notebook computers, desktop computers, mobile devices, printers, copiers, scanners, facsimile machines, and radios. Unprotected communication paths are exposed to the possibility of interception and modification. Protecting the confidentiality and integrity of information can be accomplished by physical or logical means. Physical protection can be achieved by using protected distribution systems. A protected distribution system is a wireline or fiber-optics telecommunications system that includes terminals and adequate electromagnetic, acoustical, electrical, and physical controls to permit its use for the unencrypted transmission of classified information. Logical protection can be achieved by employing encryption techniques.
Organizations that rely on commercial providers who offer transmission services as commodity services rather than as fully dedicated services may find it difficult to obtain the necessary assurances regarding the implementation of needed controls for transmission confidentiality and integrity. In such situations, organizations determine what types of confidentiality or integrity services are available in standard, commercial telecommunications service packages. If it is not feasible to obtain the necessary controls and assurances of control effectiveness through appropriate contracting vehicles, organizations can implement appropriate compensating controls.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · SC-8 — Direct NIST identifier reference. GovRAMP source matrix
System and Communications Protection · Enhancement
SC-8(1) · Cryptographic Protection
View parent controlControl statement and discussion
NIST control statement
Implement cryptographic mechanisms to [Selection (one-or-more): prevent unauthorized disclosure of information; detect changes to information] during transmission.
Discussion
Encryption protects information from unauthorized disclosure and modification during transmission. Cryptographic mechanisms that protect the confidentiality and integrity of information during transmission include TLS and IPSec. Cryptographic mechanisms used to protect information integrity include cryptographic hash functions that have applications in digital signatures, checksums, and message authentication codes.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · SC-8 (1) — Direct NIST identifier reference. GovRAMP source matrix
System and Communications Protection · Enhancement
SC-8(2) · Pre- and Post-transmission Handling
View parent controlControl statement and discussion
NIST control statement
Maintain the [Selection (one-or-more): confidentiality; integrity] of information during preparation for transmission and during reception.
Discussion
Information can be unintentionally or maliciously disclosed or modified during preparation for transmission or during reception, including during aggregation, at protocol transformation points, and during packing and unpacking. Such unauthorized disclosures or modifications compromise the confidentiality or integrity of the information.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Enhancement
SC-8(3) · Cryptographic Protection for Message Externals
View parent controlControl statement and discussion
NIST control statement
Implement cryptographic mechanisms to protect message externals unless otherwise protected by [Assignment: alternative physical controls].
Discussion
Cryptographic protection for message externals addresses protection from the unauthorized disclosure of information. Message externals include message headers and routing information. Cryptographic protection prevents the exploitation of message externals and applies to internal and external networks or links that may be visible to individuals who are not authorized users. Header and routing information is sometimes transmitted in clear text (i.e., unencrypted) because the information is not identified by organizations as having significant value or because encrypting the information can result in lower network performance or higher costs. Alternative physical controls include protected distribution systems.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Enhancement
SC-8(4) · Conceal or Randomize Communications
View parent controlControl statement and discussion
NIST control statement
Implement cryptographic mechanisms to conceal or randomize communication patterns unless otherwise protected by [Assignment: alternative physical controls].
Discussion
Concealing or randomizing communication patterns addresses protection from unauthorized disclosure of information. Communication patterns include frequency, periods, predictability, and amount. Changes to communications patterns can reveal information with intelligence value, especially when combined with other available information related to the mission and business functions of the organization. Concealing or randomizing communications prevents the derivation of intelligence based on communications patterns and applies to both internal and external networks or links that may be visible to individuals who are not authorized users. Encrypting the links and transmitting in continuous, fixed, or random patterns prevents the derivation of intelligence from the system communications patterns. Alternative physical controls include protected distribution systems.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Enhancement
SC-8(5) · Protected Distribution System
View parent controlControl statement and discussion
NIST control statement
Implement [Assignment: protected distribution system] to [Selection (one-or-more): prevent unauthorized disclosure of information; detect changes to information] during transmission.
Discussion
The purpose of a protected distribution system is to deter, detect, and/or make difficult physical access to the communication lines that carry national security information.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Base control
SC-10 · Network Disconnect
Control statement and discussion
NIST control statement
Terminate the network connection associated with a communications session at the end of the session or after [Assignment: time period] of inactivity.
Discussion
Network disconnect applies to internal and external networks. Terminating network connections associated with specific communications sessions includes de-allocating TCP/IP address or port pairs at the operating system level and de-allocating the networking assignments at the application level if multiple application sessions are using a single operating system-level network connection. Periods of inactivity may be established by organizations and include time periods by type of network access or for specific network accesses.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · SC-10 — Direct NIST identifier reference. GovRAMP source matrix
System and Communications Protection · Base control
SC-11 · Trusted Path
Control statement and discussion
NIST control statement
a. Provide a [Selection (one): physically; logically] isolated trusted communications path for communications between the user and the trusted components of the system; and
b. Permit users to invoke the trusted communications path for communications between the user and the following security functions of the system, including at a minimum, authentication and re-authentication: [Assignment: security functions].
Discussion
Trusted paths are mechanisms by which users can communicate (using input devices such as keyboards) directly with the security functions of systems with the requisite assurance to support security policies. Trusted path mechanisms can only be activated by users or the security functions of organizational systems. User responses that occur via trusted paths are protected from modification by and disclosure to untrusted applications. Organizations employ trusted paths for trustworthy, high-assurance connections between security functions of systems and users, including during system logons. The original implementations of trusted paths employed an out-of-band signal to initiate the path, such as using the <BREAK> key, which does not transmit characters that can be spoofed. In later implementations, a key combination that could not be hijacked was used (e.g., the <CTRL> + <ALT> + <DEL> keys). Such key combinations, however, are platform-specific and may not provide a trusted path implementation in every case. The enforcement of trusted communications paths is provided by a specific implementation that meets the reference monitor concept.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Enhancement
SC-11(1) · Irrefutable Communications Path
View parent controlControl statement and discussion
NIST control statement
(a) Provide a trusted communications path that is irrefutably distinguishable from other communications paths; and
(b) Initiate the trusted communications path for communications between the [Assignment: security functions] of the system and the user.
Discussion
An irrefutable communications path permits the system to initiate a trusted path, which necessitates that the user can unmistakably recognize the source of the communication as a trusted system component. For example, the trusted path may appear in an area of the display that other applications cannot access or be based on the presence of an identifier that cannot be spoofed.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Base control
SC-12 · Cryptographic Key Establishment and Management
Control statement and discussion
NIST control statement
Establish and manage cryptographic keys when cryptography is employed within the system in accordance with the following key management requirements: [Assignment: requirements].
Discussion
Cryptographic key management and establishment can be performed using manual procedures or automated mechanisms with supporting manual procedures. Organizations define key management requirements in accordance with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines and specify appropriate options, parameters, and levels. Organizations manage trust stores to ensure that only approved trust anchors are part of such trust stores. This includes certificates with visibility external to organizational systems and certificates related to the internal operations of systems. [NIST CMVP](#1acdc775-aafb-4d11-9341-dc6a822e9d38) and [NIST CAVP](#84dc1b0c-acb7-4269-84c4-00dbabacd78c) provide additional information on validated cryptographic modules and algorithms that can be used in cryptographic key management and establishment.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · SC-12 — Direct NIST identifier reference. GovRAMP source matrix
System and Communications Protection · Enhancement
SC-12(1) · Availability
View parent controlControl statement and discussion
NIST control statement
Maintain availability of information in the event of the loss of cryptographic keys by users.
Discussion
Escrowing of encryption keys is a common practice for ensuring availability in the event of key loss. A forgotten passphrase is an example of losing a cryptographic key.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
System and Communications Protection · Enhancement
SC-12(2) · Symmetric Keys
View parent controlControl statement and discussion
NIST control statement
Produce, control, and distribute symmetric cryptographic keys using [Selection (one): NIST FIPS-validated; NSA-approved] key management technology and processes.
Discussion
[SP 800-56A](#20957dbb-6a1e-40a2-b38a-66f67d33ac2e), [SP 800-56B](#0d083d8a-5cc6-46f1-8d79-3081d42bcb75) , and [SP 800-56C](#eef62b16-c796-4554-955c-505824135b8a) provide guidance on cryptographic key establishment schemes and key derivation methods. [SP 800-57-1](#110e26af-4765-49e1-8740-6750f83fcda1), [SP 800-57-2](#e7942589-e267-4a5a-a3d9-f39a7aae81f0) , and [SP 800-57-3](#8306620b-1920-4d73-8b21-12008528595f) provide guidance on cryptographic key management.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.