NIST800-SC-7 SC-7 Boundary Protection
NIST800-SC-7 in NIST SP 800-53 Rev 5 (NIST SP 800-53 Rev 5, Release 5.2.0). All NIST SP 800-53 Rev 5 controls held. Open NIST SP 800-53 Rev 5 on the standards site.
The control as we hold it
SC-7 Boundary Protection. a. Monitor and control communications at the external managed interfaces to the system and at key internal managed interfaces within the system; b. Implement subnetworks for publicly accessible system components that are [Selection: physically; logically] separated from internal organizational networks; and c. Connect to external networks or systems only through managed interfaces consisting of boundary protection devices arranged in accordance with an organizational security and privacy architecture.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
SOC 2
- SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10) (closest match)
- SOC2-CC6.1 CC6.1 Logical access security over protected information assets (closest match)
- SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary (closest match)
HIPAA Security Rule
- 164.308(a)(4)(ii)(A) Isolating Health Care Clearinghouse Functions (Required if applicable) (closest match)
- 164.308(a)(5)(ii)(B) Protection from Malicious Software (Addressable) (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: SC - System and Communications Protection), in our words, not a statement of the standard and not binding on an assessor.
- the system and communications protection policy
- the boundary, encryption and key records
- the monitoring records