id: "SC-07(19)" title: "Block Communication from Non-organizationally Configured Hosts" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-07.19" priority: "P1" implementation_level: "system" parent: "SC-07" enhancement: True


Statement

Block inbound and outbound communications traffic between {{ insert: param, sc-07.19_odp }} that are independently configured by end users and external service providers.

Guidance

Communication clients independently configured by end users and external service providers include instant messaging clients and video conferencing software and applications. Traffic blocking does not apply to communication clients that are configured by organizations to perform authorized functions.

Assessment Objective: inbound communications traffic is blocked between {{ insert: param, sc-07.19_odp }} that are independently configured by end users and external service providers;

Assessment Objective: outbound communications traffic is blocked between {{ insert: param, sc-07.19_odp }} that are independently configured by end users and external service providers.

System and communications protection policy

procedures addressing boundary protection

system design documentation

system hardware and software

system architecture

system configuration settings and associated documentation

list of communication clients independently configured by end users and external service providers

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

organizational personnel with boundary protection responsibilities

Mechanisms supporting and/or implementing the blocking of inbound and outbound communications traffic between communication clients independently configured by end users and external service providers