id: "SC-18" title: "Mobile Code" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-18" priority: "P1" implementation_level: "organization" enhancements: - sc-18.1 - sc-18.2 - sc-18.3 - sc-18.4 - sc-18.5


Define acceptable and unacceptable mobile code and mobile code technologies; and

Authorize, monitor, and control the use of mobile code within the system.

Guidance

Mobile code includes any program, application, or content that can be transmitted across a network (e.g., embedded in an email, document, or website) and executed on a remote system. Decisions regarding the use of mobile code within organizational systems are based on the potential for the code to cause damage to the systems if used maliciously. Mobile code technologies include Java applets, JavaScript, HTML5, WebGL, and VBScript. Usage restrictions and implementation guidelines apply to both the selection and use of mobile code installed on servers and mobile code downloaded and executed on individual workstations and devices, including notebook computers and smart phones. Mobile code policy and procedures address specific actions taken to prevent the development, acquisition, and introduction of unacceptable mobile code within organizational systems, including requiring mobile code to be digitally signed by a trusted source.

Assessment Objective: acceptable mobile code is defined;

Assessment Objective: unacceptable mobile code is defined;

Assessment Objective: acceptable mobile code technologies are defined;

Assessment Objective: unacceptable mobile code technologies are defined;

Assessment Objective: the use of mobile code is authorized within the system;

Assessment Objective: the use of mobile code is monitored within the system;

Assessment Objective: the use of mobile code is controlled within the system.

System and communications protection policy

procedures addressing mobile code

mobile code implementation policy and procedures

list of acceptable mobile code and mobile code technologies

list of unacceptable mobile code and mobile technologies

authorization records

system monitoring records

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

organizational personnel with responsibilities for managing mobile code

Organizational process for authorizing, monitoring, and controlling mobile code

mechanisms supporting and/or implementing the management of mobile code

mechanisms supporting and/or implementing the monitoring of mobile code