Controls & assessment objectives
16 controls
- SC.L2-3.13.1SC · System and Communications ProtectionLevel 2CMMC L2
Boundary Protection [CUI Data]
Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems.
- 8objectives
- 1examples
- 0threads
- SC.L2-3.13.2SC · System and Communications ProtectionLevel 2CMMC L2
Security Engineering
Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.
- 6objectives
- 1examples
- 0threads
- SC.L2-3.13.3SC · System and Communications ProtectionLevel 2CMMC L2
Role Separation
Separate user functionality from system management functionality.
- 3objectives
- 1examples
- 0threads
- SC.L2-3.13.4SC · System and Communications ProtectionLevel 2CMMC L2
Shared Resource Control
Prevent unauthorized and unintended information transfer via shared system resources.
- 1objectives
- 1examples
- 0threads
- SC.L2-3.13.5SC · System and Communications ProtectionLevel 2CMMC L2
Public-access System Separation [CUI Data]
Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.
- 2objectives
- 1examples
- 0threads
- SC.L2-3.13.6SC · System and Communications ProtectionLevel 2CMMC L2
Network Communication By Exception
Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).
- 2objectives
- 1examples
- 0threads
- SC.L2-3.13.7SC · System and Communications ProtectionLevel 2CMMC L2
Split Tunneling
Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).
- 1objectives
- 1examples
- 0threads
- SC.L2-3.13.8SC · System and Communications ProtectionLevel 2CMMC L2
Data in Transit
Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.
- 3objectives
- 1examples
- 0threads
- SC.L2-3.13.9SC · System and Communications ProtectionLevel 2CMMC L2
Connections Termination
Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.
- 3objectives
- 1examples
- 0threads
- SC.L2-3.13.10SC · System and Communications ProtectionLevel 2CMMC L2
Key Management
Establish and manage cryptographic keys for cryptography employed in organizational systems.
- 2objectives
- 1examples
- 0threads
- SC.L2-3.13.11SC · System and Communications ProtectionLevel 2CMMC L2
CUI Encryption
Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.
- 1objectives
- 1examples
- 0threads
- SC.L2-3.13.12SC · System and Communications ProtectionLevel 2CMMC L2
Collaborative Device Control
Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.
- 3objectives
- 1examples
- 0threads
- SC.L2-3.13.13SC · System and Communications ProtectionLevel 2CMMC L2
Mobile Code
Control and monitor the use of mobile code.
- 2objectives
- 1examples
- 0threads
- SC.L2-3.13.14SC · System and Communications ProtectionLevel 2CMMC L2
Voice Over Internet Protocol
Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.
- 2objectives
- 1examples
- 0threads
- SC.L2-3.13.15SC · System and Communications ProtectionLevel 2CMMC L2
Communications Authenticity
Protect the authenticity of communications sessions.
- 1objectives
- 1examples
- 0threads
- SC.L2-3.13.16SC · System and Communications ProtectionLevel 2CMMC L2
Data At Rest
Protect the confidentiality of CUI at rest.
- 1objectives
- 1examples
- 0threads