NIST 800-53 Rev 5

424 controls available

SC-7(21)high

Isolation of System Components

System and Communications Protection

Control Statement

Employ boundary protection mechanisms to isolate {{ insert: param, sc-07.21_odp.01 }} supporting {{ insert: param, sc-07.21_odp.02 }}.

Discussion

Organizations can isolate system components that perform different mission or business functions. Such isolation limits unauthorized information flows among system components and provides the opportunity to deploy greater levels of protection for selected system components. Isolating system components with boundary protection mechanisms provides the capability for increased protection of individual system components and to more effectively control information flows between those components. Isolating system components provides enhanced protection that limits the potential harm from hostile cyber-attacks and errors. The degree of isolation varies depending upon the mechanisms chosen. Boundary protection mechanisms include routers, gateways, and firewalls that separate system components into physically separate networks or subnetworks; cross-domain devices that separate subnetworks; virtualization techniques; and the encryption of information flows among system components using distinct encryption keys.

Framework
NIST SP 800-53 Rev 5
Family
System and Communications Protection
Baselines
high

Related Frameworks

4 paths across 1 framework
CCI4 mappings
CCI-002412
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002413
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002414
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002415
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

79 STIGs reach this control through 70 CCIs. Expand a row to see the responsible NICE and O*NET roles.

Operating System — Server

1 STIG

Network Device

63 STIGs
Router Security Requirements Guide
52024-05-2835 of 108 findings match
Router Security Requirements Guide
V5R22025-09-1035 of 123 findings match
Show 55 more STIGs in this category →
Firewall Security Requirements Guide
32024-12-047 of 34 findings match
Firewall Security Requirements Guide
V3R32025-09-227 of 35 findings match
Application Layer Gateway Security Requirements Guide
V2R32025-09-155 of 160 findings match
Layer 2 Switch Security Requirements Guide
V3R42026-02-123 of 36 findings match
Layer 2 Switch Security Requirements Guide
32025-03-052 of 28 findings match
SDN Controller Security Requirements Guide
22024-05-282 of 34 findings match
Cisco ASA VPN Security Technical Implementation Guide
V2R22024-08-221 of 41 findings match

Web / Application Server

2 STIGs

Virtualization / Container

9 STIGs

Cloud / Identity Service

1 STIG

Endpoint Security Management

3 STIGs