id: "SC-07(19)" title: "Block Communication from Non-organizationally Configured Hosts" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-07.19" priority: "P1" implementation_level: "system" parent: "SC-07" enhancement: True
Statement
Block inbound and outbound communications traffic between {{ insert: param, sc-07.19_odp }} that are independently configured by end users and external service providers.
Guidance
Communication clients independently configured by end users and external service providers include instant messaging clients and video conferencing software and applications. Traffic blocking does not apply to communication clients that are configured by organizations to perform authorized functions.
Assessment Objective: inbound communications traffic is blocked between {{ insert: param, sc-07.19_odp }} that are independently configured by end users and external service providers;
Assessment Objective: outbound communications traffic is blocked between {{ insert: param, sc-07.19_odp }} that are independently configured by end users and external service providers.
System and communications protection policy
procedures addressing boundary protection
system design documentation
system hardware and software
system architecture
system configuration settings and associated documentation
list of communication clients independently configured by end users and external service providers
system audit records
system security plan
other relevant documents or records
System/network administrators
organizational personnel with information security responsibilities
organizational personnel with boundary protection responsibilities
Mechanisms supporting and/or implementing the blocking of inbound and outbound communications traffic between communication clients independently configured by end users and external service providers