id: "SC-07(04)" title: "External Telecommunications Services" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-07.04" priority: "P1" implementation_level: "organization" parent: "SC-07" enhancement: True


Implement a managed interface for each external telecommunication service;

Establish a traffic flow policy for each managed interface;

Protect the confidentiality and integrity of the information being transmitted across each interface;

Document each exception to the traffic flow policy with a supporting mission or business need and duration of that need;

Review exceptions to the traffic flow policy {{ insert: param, sc-07.04_odp }} and remove exceptions that are no longer supported by an explicit mission or business need;

Prevent unauthorized exchange of control plane traffic with external networks;

Publish information to enable remote networks to detect unauthorized control plane traffic from internal networks; and

Filter unauthorized control plane traffic from external networks.

Guidance

External telecommunications services can provide data and/or voice communications services. Examples of control plane traffic include Border Gateway Protocol (BGP) routing, Domain Name System (DNS), and management protocols. See SP 800-189 for additional information on the use of the resource public key infrastructure (RPKI) to protect BGP routes and detect unauthorized BGP announcements.

Assessment Objective: a managed interface is implemented for each external telecommunication service;

Assessment Objective: a traffic flow policy is established for each managed interface;

Assessment Objective: the confidentiality of the information being transmitted across each interface is protected;

Assessment Objective: the integrity of the information being transmitted across each interface is protected;

Assessment Objective: each exception to the traffic flow policy is documented with a supporting mission or business need and duration of that need;

Assessment Objective: exceptions to the traffic flow policy are reviewed {{ insert: param, sc-07.04_odp }};

Assessment Objective: exceptions to the traffic flow policy that are no longer supported by an explicit mission or business need are removed;

Assessment Objective: unauthorized exchanges of control plan traffic with external networks are prevented;

Assessment Objective: information is published to enable remote networks to detect unauthorized control plane traffic from internal networks;

Assessment Objective: unauthorized control plane traffic is filtered from external networks.

System and communications protection policy

traffic flow policy

information flow control policy

procedures addressing boundary protection

system security architecture

system design documentation

boundary protection hardware and software

system architecture and configuration documentation

system configuration settings and associated documentation

records of traffic flow policy exceptions

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

organizational personnel with boundary protection responsibilities

Organizational processes for documenting and reviewing exceptions to the traffic flow policy

organizational processes for removing exceptions to the traffic flow policy

mechanisms implementing boundary protection capabilities

managed interfaces implementing traffic flow policy