Frameworks / NIST SP 800-53 Rev 5 MODERATE / SC-7 NIST SP 800-53 Rev 5 MODERATE
SC System and Communications Protection
NIST SP 800-53 Rev 5 MODERATE SC-7: Boundary Protection Monitor/control communications at external boundary and key internal boundaries; implement subnetworks for publicly accessible components.
What else in your programme already covers this This control maps to 75 controls across 25 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
1.2.6 Security features for insecure services defined 1.2.7 NSC rule sets reviewed every six months 1.3.1 Inbound traffic to CDE restricted 1.3.2 Outbound traffic from CDE restricted 1.3.3 NSCs between wireless and CDE 1.4.1 NSCs between trusted and untrusted networks 1.4.2 Inbound traffic from untrusted networks restricted 1.4.3 Anti-spoofing measures implemented 1.4.4 Account data not stored on internet-accessible systems 1.4.5 Internal IP and routing information protected 11.4.6 Segmentation testing (service providers) every 6 months CIS-12.2 Establish and Maintain a Secure Network Architecture CIS-13.10 Perform Application Layer Filtering CIS-13.4 Perform Traffic Filtering Between Network Segments CIS-13.8 Deploy a Network Intrusion Prevention Solution CIS-3.12 Segment Data Processing and Storage Based on Sensitivity CIS-4.4 Implement and Manage a Firewall on Servers CIS-4.5 Implement and Manage a Firewall on End-User Devices CIS-9.2 Use DNS Filtering Services ASBv3-GS-2 Define and implement enterprise segmentation/separation of duties strategy ASBv3-GS-4 Define and implement network security strategy ASBv3-NS-6 Deploy web application firewall NS-1 Establish network segmentation boundaries NS-2 Secure cloud services with network controls NS-3 Deploy firewall at the edge of enterprise network C5-COS-01 Technical safeguards C5-COS-02 Security requirements for connections in the Cloud Service Provider's network C5-COS-03 Monitoring of connections in the Cloud Service Provider's network C5-COS-04 Cross-network access C5-COS-06 Segregation of data traffic in jointly used network environments C5-PSS-10 Software Defined Networking 7.12 Cabling security 8.12 Data leakage prevention 8.16 Monitoring activities 8.20 Networks security 8.22 Segregation of networks 8.23 Web filtering 8.12 Data leakage prevention 8.16 Monitoring activities 8.20 Networks security 8.21 Security of network services 8.22 Segregation of networks ANSSI-HYG-17 Enable and Configure the Local Firewall on Workstations ANSSI-HYG-19 Segment the Network and Partition the Zones ANSSI-HYG-22 Put in Place a Secure Internet Access Gateway ANSSI-HYG-23 Partition Internet Facing Services from the Rest of the Information System ASD37-22 Network segmentation (Excellent) ASD37-25 Software firewall - inbound (Very Good) ASD37-32 Network-based IDS/IPS (Limited) NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage SOC2-CC6.1 Implements logical access security software, infrastructure and architectures over protected information assets SOC2-CC6.6 Measures against threats outside system boundaries are implemented CE-FW.1 Boundary Firewalls Deployed CE-FW.4 Approve and Document Inbound Rules CBPR-PR-32 Detection, prevention and response measures AUCDR-IS-2 Secure the network and systems within the data environment 6.10.1 Network security management 3.13.1e Create Diversity in System Components to Limit Malicious Code Propagation Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in SC System and Communications Protection Query this from an agent The graph holds this control, the 75 it maps to, and the evidence behind each claim, over MCP and REST.