NIST 800-53 Rev 5

424 controls available

SC-18moderatehigh

Mobile Code

System and Communications Protection

Control Statement

Define acceptable and unacceptable mobile code and mobile code technologies; and Authorize, monitor, and control the use of mobile code within the system.

Discussion

Mobile code includes any program, application, or content that can be transmitted across a network (e.g., embedded in an email, document, or website) and executed on a remote system. Decisions regarding the use of mobile code within organizational systems are based on the potential for the code to cause damage to the systems if used maliciously. Mobile code technologies include Java applets, JavaScript, HTML5, WebGL, and VBScript. Usage restrictions and implementation guidelines apply to both the selection and use of mobile code installed on servers and mobile code downloaded and executed on individual workstations and devices, including notebook computers and smart phones. Mobile code policy and procedures address specific actions taken to prevent the development, acquisition, and introduction of unacceptable mobile code within organizational systems, including requiring mobile code to be digitally signed by a trusted source.

Framework
NIST SP 800-53 Rev 5
Family
System and Communications Protection
Baselines
moderate, high

Related Frameworks

25 paths across 3 frameworks
SCF1 mapping
END-10Mobile Code
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
NIST 800-1711 mapping
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI23 mappings
CCI-001160
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001161
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001162
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001163
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001164
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001165
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001197
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001198
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · equivalent
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001166
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001167
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent

+13 more (top 10 by confidence shown)

Related STIGs

52 STIGs reach this control through 22 CCIs. Expand a row to see the responsible NICE and O*NET roles.

Operating System - Server

4 STIGs
Solaris 11 X86 Security Technical Implementation Guide
V3R52026-02-192 of 216 findings match

Operating System - Mainframe

2 STIGs
Mainframe Product Security Requirements Guide
32024-12-056 of 193 findings match
Mainframe Product Security Requirements Guide
V3R42025-09-106 of 194 findings match

Network Device

8 STIGs

Web / Application Server

8 STIGs

Endpoint Security Management

5 STIGs

Productivity Application

5 STIGs

Uncategorized

20 STIGs
Show 12 more STIGs in this category →
Mainframe Product Security Requirements Guide
V3R52026-05-236 of 194 findings match
Application Layer Gateway Security Requirements Guide
V2R42026-05-233 of 160 findings match
Solaris 11 X86 Security Technical Implementation Guide
V3R62026-05-132 of 214 findings match
Application Server Security Requirements Guide
V4R52026-06-291 of 137 findings match
Web Server Security Requirements Guide
V4R52026-05-231 of 126 findings match