πΌ SC-7 Boundary Protection
- Contextual name: πΌ SC-7 Boundary Protection
- ID:
/frameworks/nist-sp-800-53-r5/sc/07
- Located in: πΌ SC System And Communications Protection
Descriptionβ
a. Monitor and control communications at the external managed interfaces to the system and at key internal managed interfaces within the system; b. Implement subnetworks for publicly accessible system components that are [Selection: physically; logically] separated from internal organizational networks; and c. Connect to external networks or systems only through managed interfaces consisting of boundary protection devices arranged in accordance with an organizational security and privacy architecture.
Similarβ
- Sections
/frameworks/aws-fsbp-v1.0.0/auto-scaling/05
/frameworks/aws-fsbp-v1.0.0/dms/01
/frameworks/aws-fsbp-v1.0.0/documentdb/03
/frameworks/aws-fsbp-v1.0.0/ec2/01
/frameworks/aws-fsbp-v1.0.0/ec2/02
/frameworks/aws-fsbp-v1.0.0/ec2/09
/frameworks/aws-fsbp-v1.0.0/ec2/10
/frameworks/aws-fsbp-v1.0.0/ec2/15
/frameworks/aws-fsbp-v1.0.0/ec2/18
/frameworks/aws-fsbp-v1.0.0/ec2/19
/frameworks/aws-fsbp-v1.0.0/ec2/21
/frameworks/aws-fsbp-v1.0.0/ec2/25
/frameworks/aws-fsbp-v1.0.0/ec2/55
/frameworks/aws-fsbp-v1.0.0/ec2/56
/frameworks/aws-fsbp-v1.0.0/ec2/57
/frameworks/aws-fsbp-v1.0.0/ec2/58
/frameworks/aws-fsbp-v1.0.0/ec2/60
/frameworks/aws-fsbp-v1.0.0/ecs/02
/frameworks/aws-fsbp-v1.0.0/eks/01
/frameworks/aws-fsbp-v1.0.0/elasticache/07
/frameworks/aws-fsbp-v1.0.0/emr/01
/frameworks/aws-fsbp-v1.0.0/emr/02
/frameworks/aws-fsbp-v1.0.0/es/02
/frameworks/aws-fsbp-v1.0.0/lambda/01
/frameworks/aws-fsbp-v1.0.0/neptune/03
/frameworks/aws-fsbp-v1.0.0/network-firewall/06
/frameworks/aws-fsbp-v1.0.0/opensearch/02
/frameworks/aws-fsbp-v1.0.0/rds/01
/frameworks/aws-fsbp-v1.0.0/rds/02
/frameworks/aws-fsbp-v1.0.0/rds/23
/frameworks/aws-fsbp-v1.0.0/redshift/01
/frameworks/aws-fsbp-v1.0.0/redshift/07
/frameworks/aws-fsbp-v1.0.0/s3/01
/frameworks/aws-fsbp-v1.0.0/s3/02
/frameworks/aws-fsbp-v1.0.0/s3/03
/frameworks/aws-fsbp-v1.0.0/s3/19
/frameworks/aws-fsbp-v1.0.0/sagemaker/01
/frameworks/aws-fsbp-v1.0.0/sagemaker/02
/frameworks/aws-fsbp-v1.0.0/service-catalog/01
/frameworks/aws-fsbp-v1.0.0/ssm/04
/frameworks/aws-fsbp-v1.0.0/waf/02
/frameworks/aws-fsbp-v1.0.0/waf/03
/frameworks/aws-fsbp-v1.0.0/waf/08
- Internal
- ID:
dec-c-898bb59e
- ID:
Similar Sections (Take Policies From)β
Similar Sections (Give Policies To)β
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ FedRAMP High Security Controls β πΌ SC-7 Boundary Protection (L)(M)(H) | 10 | 6 | 33 | |
πΌ FedRAMP Low Security Controls β πΌ SC-7 Boundary Protection (L)(M)(H) | 23 | |||
πΌ NIST CSF v2.0 β πΌ DE.CM-01: Networks and network services are monitored to find potentially adverse events | 83 | |||
πΌ NIST CSF v2.0 β πΌ PR.DS-01: The confidentiality, integrity, and availability of data-at-rest are protected | 82 | |||
πΌ NIST CSF v2.0 β πΌ PR.DS-02: The confidentiality, integrity, and availability of data-in-transit are protected | 69 | |||
πΌ NIST CSF v2.0 β πΌ PR.DS-10: The confidentiality, integrity, and availability of data-in-use are protected | 67 | |||
πΌ NIST CSF v2.0 β πΌ PR.IR-01: Networks and environments are protected from unauthorized logical access and usage | 40 |