id: "SC-05" title: "Denial-of-service Protection" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-05" priority: "P1" implementation_level: "system" enhancements: - sc-5.1 - sc-5.2 - sc-5.3


{{ insert: param, sc-05_odp.02 }} the effects of the following types of denial-of-service events: {{ insert: param, sc-05_odp.01 }} ; and

Employ the following controls to achieve the denial-of-service objective: {{ insert: param, sc-05_odp.03 }}.

Guidance

Denial-of-service events may occur due to a variety of internal and external causes, such as an attack by an adversary or a lack of planning to support organizational needs with respect to capacity and bandwidth. Such attacks can occur across a wide range of network protocols (e.g., IPv4, IPv6). A variety of technologies are available to limit or eliminate the origination and effects of denial-of-service events. For example, boundary protection devices can filter certain types of packets to protect system components on internal networks from being directly affected by or the source of denial-of-service attacks. Employing increased network capacity and bandwidth combined with service redundancy also reduces the susceptibility to denial-of-service events.

Assessment Objective: the effects of {{ insert: param, sc-05_odp.01 }} are {{ insert: param, sc-05_odp.02 }};

Assessment Objective: {{ insert: param, sc-05_odp.03 }} are employed to achieve the denial-of-service protection objective.

System and communications protection policy

procedures addressing denial-of-service protection

system design documentation

list of denial-of-service attacks requiring employment of security safeguards to protect against or limit effects of such attacks

list of security safeguards protecting against or limiting the effects of denial-of-service attacks

system configuration settings and associated documentation

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

organizational personnel with incident response responsibilities

system developer

Mechanisms protecting against or limiting the effects of denial-of-service attacks