NIST 800-53 Rev 5

424 controls available

SC-7(4)moderatehigh

External Telecommunications Services

System and Communications Protection

Control Statement

Implement a managed interface for each external telecommunication service; Establish a traffic flow policy for each managed interface; Protect the confidentiality and integrity of the information being transmitted across each interface; Document each exception to the traffic flow policy with a supporting mission or business need and duration of that need; Review exceptions to the traffic flow policy {{ insert: param, sc-07.04_odp }} and remove exceptions that are no longer supported by an explicit mission or business need; Prevent unauthorized exchange of control plane traffic with external networks; Publish information to enable remote networks to detect unauthorized control plane traffic from internal networks; and Filter unauthorized control plane traffic from external networks.

Discussion

External telecommunications services can provide data and/or voice communications services. Examples of control plane traffic include Border Gateway Protocol (BGP) routing, Domain Name System (DNS), and management protocols. See [SP 800-189](#f5edfe51-d1f2-422e-9b27-5d0e90b49c72) for additional information on the use of the resource public key infrastructure (RPKI) to protect BGP routes and detect unauthorized BGP announcements.

Framework
NIST SP 800-53 Rev 5
Family
System and Communications Protection
Baselines
moderate, high

Related Frameworks

10 paths across 1 framework
CCI10 mappings
CCI-001102
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001103
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001105
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001106
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001107
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001108
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002396
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004869
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004870
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004871
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

79 STIGs reach this control through 70 CCIs. Expand a row to see the responsible NICE and O*NET roles.

Operating System — Server

1 STIG

Network Device

63 STIGs
Router Security Requirements Guide
52024-05-2835 of 108 findings match
Router Security Requirements Guide
V5R22025-09-1035 of 123 findings match
Show 55 more STIGs in this category →
Firewall Security Requirements Guide
32024-12-047 of 34 findings match
Firewall Security Requirements Guide
V3R32025-09-227 of 35 findings match
Application Layer Gateway Security Requirements Guide
V2R32025-09-155 of 160 findings match
Layer 2 Switch Security Requirements Guide
V3R42026-02-123 of 36 findings match
Layer 2 Switch Security Requirements Guide
32025-03-052 of 28 findings match
SDN Controller Security Requirements Guide
22024-05-282 of 34 findings match
Cisco ASA VPN Security Technical Implementation Guide
V2R22024-08-221 of 41 findings match

Web / Application Server

2 STIGs

Virtualization / Container

9 STIGs

Cloud / Identity Service

1 STIG

Endpoint Security Management

3 STIGs