id: "SC-07(04)" title: "External Telecommunications Services" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-07.04" priority: "P1" implementation_level: "organization" parent: "SC-07" enhancement: True
Implement a managed interface for each external telecommunication service;
Establish a traffic flow policy for each managed interface;
Protect the confidentiality and integrity of the information being transmitted across each interface;
Document each exception to the traffic flow policy with a supporting mission or business need and duration of that need;
Review exceptions to the traffic flow policy {{ insert: param, sc-07.04_odp }} and remove exceptions that are no longer supported by an explicit mission or business need;
Prevent unauthorized exchange of control plane traffic with external networks;
Publish information to enable remote networks to detect unauthorized control plane traffic from internal networks; and
Filter unauthorized control plane traffic from external networks.
Guidance
External telecommunications services can provide data and/or voice communications services. Examples of control plane traffic include Border Gateway Protocol (BGP) routing, Domain Name System (DNS), and management protocols. See SP 800-189 for additional information on the use of the resource public key infrastructure (RPKI) to protect BGP routes and detect unauthorized BGP announcements.
Assessment Objective: a managed interface is implemented for each external telecommunication service;
Assessment Objective: a traffic flow policy is established for each managed interface;
Assessment Objective: the confidentiality of the information being transmitted across each interface is protected;
Assessment Objective: the integrity of the information being transmitted across each interface is protected;
Assessment Objective: each exception to the traffic flow policy is documented with a supporting mission or business need and duration of that need;
Assessment Objective: exceptions to the traffic flow policy are reviewed {{ insert: param, sc-07.04_odp }};
Assessment Objective: exceptions to the traffic flow policy that are no longer supported by an explicit mission or business need are removed;
Assessment Objective: unauthorized exchanges of control plan traffic with external networks are prevented;
Assessment Objective: information is published to enable remote networks to detect unauthorized control plane traffic from internal networks;
Assessment Objective: unauthorized control plane traffic is filtered from external networks.
System and communications protection policy
traffic flow policy
information flow control policy
procedures addressing boundary protection
system security architecture
system design documentation
boundary protection hardware and software
system architecture and configuration documentation
system configuration settings and associated documentation
records of traffic flow policy exceptions
system audit records
system security plan
other relevant documents or records
System/network administrators
organizational personnel with information security responsibilities
organizational personnel with boundary protection responsibilities
Organizational processes for documenting and reviewing exceptions to the traffic flow policy
organizational processes for removing exceptions to the traffic flow policy
mechanisms implementing boundary protection capabilities
managed interfaces implementing traffic flow policy