id: "SC-07(10)" title: "Prevent Exfiltration" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-07.10" priority: "P1" implementation_level: "system" parent: "SC-07" enhancement: True


Prevent the exfiltration of information; and

Conduct exfiltration tests {{ insert: param, sc-07.10_odp }}.

Guidance

Prevention of exfiltration applies to both the intentional and unintentional exfiltration of information. Techniques used to prevent the exfiltration of information from systems may be implemented at internal endpoints, external boundaries, and across managed interfaces and include adherence to protocol formats, monitoring for beaconing activity from systems, disconnecting external network interfaces except when explicitly needed, employing traffic profile analysis to detect deviations from the volume and types of traffic expected, call backs to command and control centers, conducting penetration testing, monitoring for steganography, disassembling and reassembling packet headers, and using data loss and data leakage prevention tools. Devices that enforce strict adherence to protocol formats include deep packet inspection firewalls and Extensible Markup Language (XML) gateways. The devices verify adherence to protocol formats and specifications at the application layer and identify vulnerabilities that cannot be detected by devices that operate at the network or transport layers. The prevention of exfiltration is similar to data loss prevention or data leakage prevention and is closely associated with cross-domain solutions and system guards that enforce information flow requirements.

Assessment Objective: the exfiltration of information is prevented;

Assessment Objective: exfiltration tests are conducted {{ insert: param, sc-07.10_odp }}.

System and communications protection policy

procedures addressing boundary protection

system design documentation

system configuration settings and associated documentation

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

organizational personnel with boundary protection responsibilities

Mechanisms implementing boundary protection capabilities that prevent the unauthorized exfiltration of information across managed interfaces