Usage Restrictions
LOW MODERATE HIGHRequirements NIST SOURCE
Requirement Context
This element is part of SC-43 — Usage Restrictions. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of SC-43 — Usage Restrictions. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Discussion (NIST Supplemental Guidance)
Usage restrictions apply to all system components including but not limited to mobile code, mobile devices, wireless access, and wired and wireless peripheral components (e.g., copiers, printers, scanners, optical devices, and other similar technologies). The usage restrictions and implementation guidelines are based on the potential for system components to cause damage to the system and help to ensure that only authorized system use occurs.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for SC-43 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- the components for which usage restrictions and implementation guidance are to be established are defined;
- usage restrictions and implementation guidelines are established for <SC-43_ODP components>;
- the use of <SC-43_ODP components> is authorized within the system;
- the use of <SC-43_ODP components> is monitored within the system;
- the use of <SC-43_ODP components> is controlled within the system.
Examine
[SELECT FROM: System and communications protection policy; usage restrictions; procedures addressing usage restrictions; implementation policy and procedures; authorization records; system monitoring records; system audit records; system security plan; other relevant documents or records].
Interview
[SELECT FROM: System/network administrators; organizational personnel with information security responsibilities; organizational personnel installing, configuring, and/or maintaining the system].
Test
[SELECT FROM: Organizational processes for authorizing, monitoring, and controlling the use of components with usage restrictions; mechanisms supporting and/or implementing, authorizing, monitoring, and controlling the use of components with usage restrictions].
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for SC-43. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- System and communications protection policy
- implementation policy and procedures
- system security plan
Testing
- Organizational processes for authorizing, monitoring, and controlling the use of components with usage restrictions
- mechanisms supporting and/or implementing, authorizing, monitoring, and controlling the use of components with usage restrictions
Other Records
- usage restrictions
- procedures addressing usage restrictions
- authorization records
- system monitoring records
- system audit records
- other relevant documents or records