External Telecommunications Services
LOW ✓ MODERATE ✓ HIGHRequirements NIST SOURCE
Requirement Context
This element is part of SC-7(4) — External Telecommunications Services. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of SC-7(4) — External Telecommunications Services. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of SC-7(4) — External Telecommunications Services. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of SC-7(4) — External Telecommunications Services. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of SC-7(4) — External Telecommunications Services. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of SC-7(4) — External Telecommunications Services. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of SC-7(4) — External Telecommunications Services. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of SC-7(4) — External Telecommunications Services. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Discussion (NIST Supplemental Guidance)
External telecommunications services can provide data and/or voice communications services. Examples of control plane traffic include Border Gateway Protocol (BGP) routing, Domain Name System (DNS), and management protocols. See SP 800-189 for additional information on the use of the resource public key infrastructure (RPKI) to protect BGP routes and detect unauthorized BGP announcements.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for SC-7(4) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- the frequency at which to review exceptions to traffic flow policy is defined;
- a managed interface is implemented for each external telecommunication service;
- a traffic flow policy is established for each managed interface;
- the confidentiality of the information being transmitted across each interface is protected;
- the integrity of the information being transmitted across each interface is protected;
- each exception to the traffic flow policy is documented with a supporting mission or business need and duration of that need;
- exceptions to the traffic flow policy are reviewed <SC-07(04)_ODP frequency>;
- exceptions to the traffic flow policy that are no longer supported by an explicit mission or business need are removed;
- unauthorized exchanges of control plan traffic with external networks are prevented;
- information is published to enable remote networks to detect unauthorized control plane traffic from internal networks;
- unauthorized control plane traffic is filtered from external networks.
Examine
[SELECT FROM: System and communications protection policy; traffic flow policy; information flow control policy; procedures addressing boundary protection; system security architecture; system design documentation; boundary protection hardware and software; system architecture and configuration documentation; system configuration settings and associated documentation; records of traffic flow policy exceptions; system audit records; system security plan; other relevant documents or records].
Interview
[SELECT FROM: System/network administrators; organizational personnel with information security responsibilities; organizational personnel with boundary protection responsibilities].
Test
[SELECT FROM: Organizational processes for documenting and reviewing exceptions to the traffic flow policy; organizational processes for removing exceptions to the traffic flow policy; mechanisms implementing boundary protection capabilities; managed interfaces implementing traffic flow policy].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for SC-7(4). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- System and communications protection policy
- traffic flow policy
- information flow control policy
- records of traffic flow policy exceptions
- system security plan
Configuration
- system security architecture
- system design documentation
- system architecture and configuration documentation
- system configuration settings and associated documentation
Testing
- Organizational processes for documenting and reviewing exceptions to the traffic flow policy
- organizational processes for removing exceptions to the traffic flow policy
- mechanisms implementing boundary protection capabilities
- managed interfaces implementing traffic flow policy
Other Records
- procedures addressing boundary protection
- boundary protection hardware and software
- system audit records
- other relevant documents or records