NIST 800-53 Rev 5

424 controls available

SC-7(8)moderatehigh

Route Traffic to Authenticated Proxy Servers

System and Communications Protection

Control Statement

Route {{ insert: param, sc-07.08_odp.01 }} to {{ insert: param, sc-07.08_odp.02 }} through authenticated proxy servers at managed interfaces.

Discussion

External networks are networks outside of organizational control. A proxy server is a server (i.e., system or application) that acts as an intermediary for clients requesting system resources from non-organizational or other organizational servers. System resources that may be requested include files, connections, web pages, or services. Client requests established through a connection to a proxy server are assessed to manage complexity and provide additional protection by limiting direct connectivity. Web content filtering devices are one of the most common proxy servers that provide access to the Internet. Proxy servers can support the logging of Transmission Control Protocol sessions and the blocking of specific Uniform Resource Locators, Internet Protocol addresses, and domain names. Web proxies can be configured with organization-defined lists of authorized and unauthorized websites. Note that proxy servers may inhibit the use of virtual private networks (VPNs) and create the potential for "man-in-the-middle" attacks (depending on the implementation).

Framework
NIST SP 800-53 Rev 5
Family
System and Communications Protection
Baselines
moderate, high

Related Frameworks

8 paths across 2 frameworks
SCF2 mappings
NET-18DNS & Content Filtering
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
NET-18.1Route Internal Traffic to Proxy Servers
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
CCI6 mappings
CCI-001112
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001113
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001114
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001169
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-001695
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002459
0.25
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • Secure Controls Framework · 2026.2 · scf_strm · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

88 STIGs reach this control through 70 CCIs. Expand a row to see the responsible NICE and O*NET roles.

Operating System - Server

1 STIG

Network Device

63 STIGs
Router Security Requirements Guide
52024-05-2835 of 108 findings match
Router Security Requirements Guide
V5R22025-09-1035 of 123 findings match
Show 55 more STIGs in this category →
Firewall Security Requirements Guide
32024-12-047 of 34 findings match
Firewall Security Requirements Guide
V3R32025-09-227 of 35 findings match
Application Layer Gateway Security Requirements Guide
V2R32025-09-155 of 160 findings match
Layer 2 Switch Security Requirements Guide
V3R42026-02-123 of 36 findings match
Layer 2 Switch Security Requirements Guide
32025-03-052 of 28 findings match
SDN Controller Security Requirements Guide
22024-05-282 of 34 findings match
Cisco ASA VPN Security Technical Implementation Guide
V2R22024-08-221 of 41 findings match

Web / Application Server

2 STIGs

Virtualization / Container

9 STIGs

Cloud / Identity Service

1 STIG

Endpoint Security Management

3 STIGs

Uncategorized

9 STIGs
Firewall Security Requirements Guide
V3R42026-05-237 of 35 findings match
Application Layer Gateway Security Requirements Guide
V2R42026-05-235 of 160 findings match
Show 1 more STIG in this category →