Mobile Code

LOW ✓ MODERATE ✓ HIGH
5 Enhancements 1 Overlay 5 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Discussion (NIST Supplemental Guidance)

Mobile code includes any program, application, or content that can be transmitted across a network (e.g., embedded in an email, document, or website) and executed on a remote system. Decisions regarding the use of mobile code within organizational systems are based on the potential for the code to cause damage to the systems if used maliciously. Mobile code technologies include Java applets, JavaScript, HTML5, WebGL, and VBScript. Usage restrictions and implementation guidelines apply to both the selection and use of mobile code installed on servers and mobile code downloaded and executed on individual workstations and devices, including notebook computers and smart phones. Mobile code policy and procedures address specific actions taken to prevent the development, acquisition, and introduction of unacceptable mobile code within organizational systems, including requiring mobile code to be digitally signed by a trusted source.

Enhancements NIST SOURCE

SC-18(1) Identify Unacceptable Code and Take Corrective Actions LOW MODERATE HIGH

Identify [unacceptable mobile code] and take [corrective actions].

Discussion

Corrective actions when unacceptable mobile code is detected include blocking, quarantine, or alerting administrators. Blocking includes preventing the transmission of word processing files with embedded macros when such macros have been determined to be unacceptable mobile code.

Open full page for SC-18(1) →
SC-18(2) Acquisition, Development, and Use LOW MODERATE HIGH

Verify that the acquisition, development, and use of mobile code to be deployed in the system meets [mobile code requirements].

Discussion

None.

Open full page for SC-18(2) →
SC-18(3) Prevent Downloading and Execution LOW MODERATE HIGH

Prevent the download and execution of [unacceptable mobile code].

Discussion

None.

Open full page for SC-18(3) →
SC-18(4) Prevent Automatic Execution LOW MODERATE HIGH

Prevent the automatic execution of mobile code in [software applications] and enforce [actions] prior to executing the code.

Discussion

Actions enforced before executing mobile code include prompting users prior to opening email attachments or clicking on web links. Preventing the automatic execution of mobile code includes disabling auto-execute features on system components that employ portable storage devices, such as compact discs, digital versatile discs, and universal serial bus devices.

Open full page for SC-18(4) →
SC-18(5) Allow Execution Only in Confined Environments LOW MODERATE HIGH

Allow execution of permitted mobile code only in confined virtual machine environments.

Discussion

Permitting the execution of mobile code only in confined virtual machine environments helps prevent the introduction of malicious code into other systems and system components.

Open full page for SC-18(5) →

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for SC-18 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. acceptable mobile code is defined;
  2. unacceptable mobile code is defined;
  3. acceptable mobile code technologies are defined;
  4. unacceptable mobile code technologies are defined;
  5. the use of mobile code is authorized within the system;
  6. the use of mobile code is monitored within the system;
  7. the use of mobile code is controlled within the system.

Examine

[SELECT FROM: System and communications protection policy; procedures addressing mobile code; mobile code implementation policy and procedures; list of acceptable mobile code and mobile code technologies; list of unacceptable mobile code and mobile technologies; authorization records; system monitoring records; system audit records; system security plan; other relevant documents or records].

Interview

[SELECT FROM: System/network administrators; organizational personnel with information security responsibilities; organizational personnel with responsibilities for managing mobile code].

Test

[SELECT FROM: Organizational process for authorizing, monitoring, and controlling mobile code; mechanisms supporting and/or implementing the management of mobile code; mechanisms supporting and/or implementing the monitoring of mobile code].

Overlays

OT/ICS Overlay SP 800-82r3

NIST SP 800-82r3 Appendix F, Table 22. Blank baseline means the control/control enhancement is not selected in that initial OT baseline.

LOW

Not applicable at this tier.

MODERATE

  • Base control: Included (matches standard baseline)

HIGH

  • Base control: Included (matches standard baseline)

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for SC-18. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • System and communications protection policy
  • mobile code implementation policy and procedures
  • system security plan

Testing

  • Organizational process for authorizing, monitoring, and controlling mobile code
  • mechanisms supporting and/or implementing the management of mobile code
  • mechanisms supporting and/or implementing the monitoring of mobile code

Other Records

  • procedures addressing mobile code
  • list of acceptable mobile code and mobile code technologies
  • list of unacceptable mobile code and mobile technologies
  • authorization records
  • system monitoring records
  • system audit records
  • other relevant documents or records