NIST SP 800-53 Rev 5 MODERATE
SC System and Communications Protection

NIST SP 800-53 Rev 5 MODERATE SC-7: Boundary Protection

Monitor/control communications at external boundary and key internal boundaries; implement subnetworks for publicly accessible components.

What else in your programme already covers this

This control maps to 75 controls across 25 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 11 controls

  • 1.2.6 Security features for insecure services defined
  • 1.2.7 NSC rule sets reviewed every six months
  • 1.3.1 Inbound traffic to CDE restricted
  • 1.3.2 Outbound traffic from CDE restricted
  • 1.3.3 NSCs between wireless and CDE
  • 1.4.1 NSCs between trusted and untrusted networks
  • 1.4.2 Inbound traffic from untrusted networks restricted
  • 1.4.3 Anti-spoofing measures implemented
  • 1.4.4 Account data not stored on internet-accessible systems
  • 1.4.5 Internal IP and routing information protected
  • 11.4.6 Segmentation testing (service providers) every 6 months

CIS Controls v8 · 8 controls

  • CIS-12.2 Establish and Maintain a Secure Network Architecture
  • CIS-13.10 Perform Application Layer Filtering
  • CIS-13.4 Perform Traffic Filtering Between Network Segments
  • CIS-13.8 Deploy a Network Intrusion Prevention Solution
  • CIS-3.12 Segment Data Processing and Storage Based on Sensitivity
  • CIS-4.4 Implement and Manage a Firewall on Servers
  • CIS-4.5 Implement and Manage a Firewall on End-User Devices
  • CIS-9.2 Use DNS Filtering Services
  • ASBv3-GS-2 Define and implement enterprise segmentation/separation of duties strategy
  • ASBv3-GS-4 Define and implement network security strategy
  • ASBv3-NS-6 Deploy web application firewall
  • NS-1 Establish network segmentation boundaries
  • NS-2 Secure cloud services with network controls
  • NS-3 Deploy firewall at the edge of enterprise network

C5 (Germany) · 6 controls

  • C5-COS-01 Technical safeguards
  • C5-COS-02 Security requirements for connections in the Cloud Service Provider's network
  • C5-COS-03 Monitoring of connections in the Cloud Service Provider's network
  • C5-COS-04 Cross-network access
  • C5-COS-06 Segregation of data traffic in jointly used network environments
  • C5-PSS-10 Software Defined Networking

ISO 27002:2022 · 6 controls

  • 7.12 Cabling security
  • 8.12 Data leakage prevention
  • 8.16 Monitoring activities
  • 8.20 Networks security
  • 8.22 Segregation of networks
  • 8.23 Web filtering

ISO 27001:2022 · 5 controls

  • 8.12 Data leakage prevention
  • 8.16 Monitoring activities
  • 8.20 Networks security
  • 8.21 Security of network services
  • 8.22 Segregation of networks
  • ANSSI-HYG-17 Enable and Configure the Local Firewall on Workstations
  • ANSSI-HYG-19 Segment the Network and Partition the Zones
  • ANSSI-HYG-22 Put in Place a Secure Internet Access Gateway
  • ANSSI-HYG-23 Partition Internet Facing Services from the Rest of the Information System
  • ASD37-22 Network segmentation (Excellent)
  • ASD37-25 Software firewall - inbound (Very Good)
  • ASD37-32 Network-based IDS/IPS (Limited)

CMMC 2.0 · 2 controls

  • NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events
  • NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage

SOC 2 · 2 controls

  • SOC2-CC6.1 Implements logical access security software, infrastructure and architectures over protected information assets
  • SOC2-CC6.6 Measures against threats outside system boundaries are implemented

UK Cyber Essentials · 2 controls

  • CE-FW.1 Boundary Firewalls Deployed
  • CE-FW.4 Approve and Document Inbound Rules
  • CBPR-PR-32 Detection, prevention and response measures
  • AUCDR-IS-2 Secure the network and systems within the data environment

DORA · 1 control

HIPAA Security Rule · 1 control

ISO 27701:2019 · 1 control

  • 6.10.1 Network security management

NIST SP 800-172 · 1 control

  • 3.13.1e Create Diversity in System Components to Limit Malicious Code Propagation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in SC System and Communications Protection

Query this from an agent

The graph holds this control, the 75 it maps to, and the evidence behind each claim, over MCP and REST.