Mobile Code
LOW ✓ MODERATE ✓ HIGHRequirements NIST SOURCE
Requirement Context
This element is part of SC-18 — Mobile Code. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of SC-18 — Mobile Code. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Discussion (NIST Supplemental Guidance)
Mobile code includes any program, application, or content that can be transmitted across a network (e.g., embedded in an email, document, or website) and executed on a remote system. Decisions regarding the use of mobile code within organizational systems are based on the potential for the code to cause damage to the systems if used maliciously. Mobile code technologies include Java applets, JavaScript, HTML5, WebGL, and VBScript. Usage restrictions and implementation guidelines apply to both the selection and use of mobile code installed on servers and mobile code downloaded and executed on individual workstations and devices, including notebook computers and smart phones. Mobile code policy and procedures address specific actions taken to prevent the development, acquisition, and introduction of unacceptable mobile code within organizational systems, including requiring mobile code to be digitally signed by a trusted source.
Enhancements NIST SOURCE
SC-18(1) Identify Unacceptable Code and Take Corrective Actions LOW MODERATE HIGH
Identify [unacceptable mobile code] and take [corrective actions].
Discussion
Corrective actions when unacceptable mobile code is detected include blocking, quarantine, or alerting administrators. Blocking includes preventing the transmission of word processing files with embedded macros when such macros have been determined to be unacceptable mobile code.
SC-18(2) Acquisition, Development, and Use LOW MODERATE HIGH
Verify that the acquisition, development, and use of mobile code to be deployed in the system meets [mobile code requirements].
Discussion
None.
SC-18(3) Prevent Downloading and Execution LOW MODERATE HIGH
Prevent the download and execution of [unacceptable mobile code].
Discussion
None.
SC-18(4) Prevent Automatic Execution LOW MODERATE HIGH
Prevent the automatic execution of mobile code in [software applications] and enforce [actions] prior to executing the code.
Discussion
Actions enforced before executing mobile code include prompting users prior to opening email attachments or clicking on web links. Preventing the automatic execution of mobile code includes disabling auto-execute features on system components that employ portable storage devices, such as compact discs, digital versatile discs, and universal serial bus devices.
SC-18(5) Allow Execution Only in Confined Environments LOW MODERATE HIGH
Allow execution of permitted mobile code only in confined virtual machine environments.
Discussion
Permitting the execution of mobile code only in confined virtual machine environments helps prevent the introduction of malicious code into other systems and system components.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for SC-18 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- acceptable mobile code is defined;
- unacceptable mobile code is defined;
- acceptable mobile code technologies are defined;
- unacceptable mobile code technologies are defined;
- the use of mobile code is authorized within the system;
- the use of mobile code is monitored within the system;
- the use of mobile code is controlled within the system.
Examine
[SELECT FROM: System and communications protection policy; procedures addressing mobile code; mobile code implementation policy and procedures; list of acceptable mobile code and mobile code technologies; list of unacceptable mobile code and mobile technologies; authorization records; system monitoring records; system audit records; system security plan; other relevant documents or records].
Interview
[SELECT FROM: System/network administrators; organizational personnel with information security responsibilities; organizational personnel with responsibilities for managing mobile code].
Test
[SELECT FROM: Organizational process for authorizing, monitoring, and controlling mobile code; mechanisms supporting and/or implementing the management of mobile code; mechanisms supporting and/or implementing the monitoring of mobile code].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for SC-18. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- System and communications protection policy
- mobile code implementation policy and procedures
- system security plan
Testing
- Organizational process for authorizing, monitoring, and controlling mobile code
- mechanisms supporting and/or implementing the management of mobile code
- mechanisms supporting and/or implementing the monitoring of mobile code
Other Records
- procedures addressing mobile code
- list of acceptable mobile code and mobile code technologies
- list of unacceptable mobile code and mobile technologies
- authorization records
- system monitoring records
- system audit records
- other relevant documents or records