id: "SC-05(02)" title: "Capacity, Bandwidth, and Redundancy" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-05.02" priority: "P1" implementation_level: "system" parent: "SC-05" enhancement: True


Statement

Manage capacity, bandwidth, or other redundancy to limit the effects of information flooding denial-of-service attacks.

Guidance

Managing capacity ensures that sufficient capacity is available to counter flooding attacks. Managing capacity includes establishing selected usage priorities, quotas, partitioning, or load balancing.

Assessment Objective

capacity, bandwidth, or other redundancies to limit the effects of information flooding denial-of-service attacks are managed.

System and communications protection policy

procedures addressing denial-of-service protection

system design documentation

system configuration settings and associated documentation

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

organizational personnel with incident response responsibilities

system developer

Mechanisms implementing the management of system bandwidth, capacity, and redundancy to limit the effects of information flooding denial-of-service attacks