← SC-7

External Telecommunications Services

LOW ✓ MODERATE ✓ HIGH
1 Overlay 5 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Discussion (NIST Supplemental Guidance)

External telecommunications services can provide data and/or voice communications services. Examples of control plane traffic include Border Gateway Protocol (BGP) routing, Domain Name System (DNS), and management protocols. See SP 800-189 for additional information on the use of the resource public key infrastructure (RPKI) to protect BGP routes and detect unauthorized BGP announcements.

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for SC-7(4) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. the frequency at which to review exceptions to traffic flow policy is defined;
  2. a managed interface is implemented for each external telecommunication service;
  3. a traffic flow policy is established for each managed interface;
  4. the confidentiality of the information being transmitted across each interface is protected;
  5. the integrity of the information being transmitted across each interface is protected;
  6. each exception to the traffic flow policy is documented with a supporting mission or business need and duration of that need;
  7. exceptions to the traffic flow policy are reviewed <SC-07(04)_ODP frequency>;
  8. exceptions to the traffic flow policy that are no longer supported by an explicit mission or business need are removed;
  9. unauthorized exchanges of control plan traffic with external networks are prevented;
  10. information is published to enable remote networks to detect unauthorized control plane traffic from internal networks;
  11. unauthorized control plane traffic is filtered from external networks.

Examine

[SELECT FROM: System and communications protection policy; traffic flow policy; information flow control policy; procedures addressing boundary protection; system security architecture; system design documentation; boundary protection hardware and software; system architecture and configuration documentation; system configuration settings and associated documentation; records of traffic flow policy exceptions; system audit records; system security plan; other relevant documents or records].

Interview

[SELECT FROM: System/network administrators; organizational personnel with information security responsibilities; organizational personnel with boundary protection responsibilities].

Test

[SELECT FROM: Organizational processes for documenting and reviewing exceptions to the traffic flow policy; organizational processes for removing exceptions to the traffic flow policy; mechanisms implementing boundary protection capabilities; managed interfaces implementing traffic flow policy].

Overlays

Showing the OT/ICS overlay for the parent control SC-7 — see the SC-7(4) entries within each baseline below.

OT/ICS Overlay SP 800-82r3

NIST SP 800-82r3 Appendix F, Table 22. Blank baseline means the control/control enhancement is not selected in that initial OT baseline.

LOW

  • Base control: Included (matches standard baseline)
  • Added: (28) (29)

MODERATE

  • Base control: Included (matches standard baseline)
  • Included: (3) (4) (5) (7) (8)
  • Added: (18) (28) (29)

HIGH

  • Base control: Included (matches standard baseline)
  • Included: (3) (4) (5) (7) (8) (18) (21)
  • Added: (28) (29)

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for SC-7(4). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • System and communications protection policy
  • traffic flow policy
  • information flow control policy
  • records of traffic flow policy exceptions
  • system security plan

Configuration

  • system security architecture
  • system design documentation
  • system architecture and configuration documentation
  • system configuration settings and associated documentation

Testing

  • Organizational processes for documenting and reviewing exceptions to the traffic flow policy
  • organizational processes for removing exceptions to the traffic flow policy
  • mechanisms implementing boundary protection capabilities
  • managed interfaces implementing traffic flow policy

Other Records

  • procedures addressing boundary protection
  • boundary protection hardware and software
  • system audit records
  • other relevant documents or records