NIST 800-53 r5 · Controls catalogue · Family SC
SC-37Out-of-band Channels
Employ the following out-of-band channels for the physical delivery or electronic transmission of {{ insert: param, sc-37_odp.02 }} to {{ insert: param, sc-37_odp.03 }}: {{ insert: param, sc-37_odp.01 }}.
Last updated: 20 August 2026 13:14 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (12)
- T1071 Application Layer Protocol Command And Control
- T1071.001 Web Protocols Command And Control
- T1071.002 File Transfer Protocols Command And Control
- T1071.003 Mail Protocols Command And Control
- T1071.004 DNS Command And Control
- T1114 Email Collection Collection
- T1114.001 Local Email Collection Collection
- T1114.002 Remote Email Collection Collection
- T1114.003 Email Forwarding Rule Collection
- T1213 Data from Information Repositories Collection
- T1213.005 Messaging Applications Collection
- T1489 Service Stop Impact
Weaknesses this control addresses (5)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | 11,000+ | Out-of-band delivery transmits sensitive data on a separate path, directly reducing exposure to unauthorized actors on the primary channel. |
CWE-522 | Insufficiently Protected Credentials | 1,600+ | Credentials or keys delivered out-of-band are not exposed to interception or inadequate protection on the main transport. |
CWE-319 | Cleartext Transmission of Sensitive Information | 1,000+ | Sensitive values are moved off the primary channel, avoiding cleartext transmission risks associated with that channel. |
CWE-300 | Channel Accessible by Non-Endpoint | 55 | An out-of-band channel is inaccessible to non-endpoints that can observe or interfere with the primary communication channel. |
CWE-523 | Unprotected Transport of Credentials | 25 | Using a distinct channel for credential transmission prevents unprotected transport over the application's normal communication path. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
| No CVEs annotated to this control yet — the per-CVE backfill is in progress. | ||||