NIST 800-53 r5 · Controls catalogue · Family SC
SC-7Boundary Protection
Monitor and control communications at the external managed interfaces to the system and at key internal managed interfaces within the system; Implement subnetworks for publicly accessible system components that are {{ insert: param, sc-07_odp }} separated from internal organizational networks; and Connect to external networks or systems only through managed interfaces consisting of boundary protection devices arranged in accordance with an organizational security and privacy architecture.
Last updated: 22 August 2026 07:11 UTC
Implementations targeting this control (27)
- aws-config-s3-bucket-public-read-prohibited S3 buckets prohibit public read access AWS::S3::Bucket partial protect enforce
- aws-config-s3-bucket-public-write-prohibited S3 buckets prohibit public write access AWS::S3::Bucket partial protect enforce CIS §2.1.4Hub S3.8
- aws-config-rds-instance-public-access-check RDS instances are not publicly accessible AWS::RDS::DBInstance partial protect enforce CIS v5 §2.2.3CIS v3 §2.3.3Hub RDS.2
- aws-config-rds-snapshots-public-prohibited RDS snapshots are not publicly restorable AWS::RDS::DBSnapshot partial recover enforce
- aws-config-incoming-ssh-disabled Security groups disallow unrestricted SSH ingress AWS::EC2::SecurityGroup encompass protect enforce
- aws-config-restricted-common-ports Restricted Common Ports AWS::EC2::SecurityGroup partial protect enforce CIS v5 §5.4CIS v3 §5.3Hub EC2.54
- aws-config-lambda-function-public-access-prohibited Lambda function policies prohibit public invocation AWS::Lambda::Function partial protect enforce
- aws-config-autoscaling-launch-config-public-ip-disabled Autoscaling Launch Config Public Ip Disabled AWS::AutoScaling::AutoScalingGroup partial protect enforce
- aws-config-dms-replication-not-public Dms Replication Not Public AWS::DMS::ReplicationInstance partial recover enforce
- aws-config-ebs-snapshot-public-restorable-check Ebs Snapshot Public Restorable Check AWS::EC2::Volume partial recover enforce
- aws-config-ec2-instance-no-public-ip Ec2 Instance No Public Ip AWS::EC2::Instance partial protect enforce
- aws-config-ec2-instances-in-vpc Ec2 Instances In Vpc AWS::EC2::Instance partial protect enforce
- aws-config-elasticsearch-in-vpc-only Elasticsearch In Vpc Only AWS::OpenSearchService::Domain partial protect enforce
- aws-config-emr-master-no-public-ip Emr Master No Public Ip AWS::EMR::Cluster partial protect enforce
- aws-config-lambda-inside-vpc Lambda Inside Vpc AWS::Lambda::Function partial protect enforce
- aws-config-no-unrestricted-route-to-igw No Unrestricted Route To Igw AWS::EC2::RouteTable partial protect enforce
- aws-config-opensearch-in-vpc-only Opensearch In Vpc Only AWS::OpenSearchService::Domain partial protect enforce
- aws-config-redshift-cluster-public-access-check Redshift Cluster Public Access Check AWS::Redshift::Cluster partial protect enforce
- aws-config-redshift-enhanced-vpc-routing-enabled Redshift Enhanced Vpc Routing Enabled AWS::Redshift::Cluster partial protect enforce
- aws-config-restricted-ssh Restricted Ssh AWS::EC2::SecurityGroup partial protect enforce CIS v5 §5.3CIS v3 §5.2Hub EC2.53
- aws-config-s3-account-level-public-access-blocks-periodic S3 Account Level Public Access Blocks Periodic AWS::S3::Bucket partial protect enforce CIS §2.1.4Hub S3.1
- aws-config-s3-bucket-level-public-access-prohibited S3 Bucket Level Public Access Prohibited AWS::S3::Bucket partial protect enforce
- aws-config-sagemaker-notebook-no-direct-internet-access Sagemaker Notebook No Direct Internet Access AWS::SageMaker::NotebookInstance partial protect enforce
- aws-config-ssm-document-not-public Ssm Document Not Public AWS::SSM::Document partial protect enforce
- aws-config-subnet-auto-assign-public-ip-disabled Subnet Auto Assign Public Ip Disabled AWS::EC2::Subnet partial protect enforce
- aws-config-vpc-default-security-group-closed Vpc Default Security Group Closed AWS::EC2::VPC partial protect enforce CIS v5 §5.5CIS v3 §5.4Hub EC2.2
- aws-config-vpc-sg-open-only-to-authorized-ports Vpc Sg Open Only To Authorized Ports AWS::EC2::VPC partial protect enforce
ATT&CK techniques this control mitigates (156)
- T1001 Data Obfuscation Command And Control
- T1001.001 Junk Data Command And Control
- T1001.002 Steganography Command And Control
- T1001.003 Protocol or Service Impersonation Command And Control
- T1008 Fallback Channels Command And Control
- T1020.001 Traffic Duplication Exfiltration
- T1021.001 Remote Desktop Protocol Lateral Movement
- T1021.002 SMB/Windows Admin Shares Lateral Movement
- T1021.003 Distributed Component Object Model Lateral Movement
- T1021.005 VNC Lateral Movement
- T1021.006 Windows Remote Management Lateral Movement
- T1029 Scheduled Transfer Exfiltration
- T1030 Data Transfer Size Limits Exfiltration
- T1036.008 Masquerade File Type Stealth
- T1041 Exfiltration Over C2 Channel Exfiltration
- T1046 Network Service Discovery Discovery
- T1048 Exfiltration Over Alternative Protocol Exfiltration
- T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol Exfiltration
- T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol Exfiltration
- T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol Exfiltration
- T1055 Process Injection Stealth, Privilege Escalation
- T1055.001 Dynamic-link Library Injection Stealth, Privilege Escalation
- T1055.002 Portable Executable Injection Stealth, Privilege Escalation
- T1055.003 Thread Execution Hijacking Stealth, Privilege Escalation
- T1055.004 Asynchronous Procedure Call Stealth, Privilege Escalation
- T1055.005 Thread Local Storage Stealth, Privilege Escalation
- T1055.008 Ptrace System Calls Stealth, Privilege Escalation
- T1055.009 Proc Memory Stealth, Privilege Escalation
- T1055.011 Extra Window Memory Injection Stealth, Privilege Escalation
- T1055.012 Process Hollowing Stealth, Privilege Escalation
- T1055.013 Process Doppelgänging Stealth, Privilege Escalation
- T1055.014 VDSO Hijacking Stealth, Privilege Escalation
- T1068 Exploitation for Privilege Escalation Privilege Escalation
- T1071 Application Layer Protocol Command And Control
- T1071.001 Web Protocols Command And Control
- T1071.002 File Transfer Protocols Command And Control
- T1071.003 Mail Protocols Command And Control
- T1071.004 DNS Command And Control
- T1071.005 Publish/Subscribe Protocols Command And Control
- T1072 Software Deployment Tools Execution, Lateral Movement
- T1078 Valid Accounts Stealth, Persistence, Privilege Escalation, Initial Access
- T1080 Taint Shared Content Lateral Movement
- T1090 Proxy Command And Control
- T1090.001 Internal Proxy Command And Control
- T1090.002 External Proxy Command And Control
- T1090.003 Multi-hop Proxy Command And Control
- T1095 Non-Application Layer Protocol Command And Control
- T1098 Account Manipulation Persistence, Privilege Escalation
- T1098.001 Additional Cloud Credentials Persistence, Privilege Escalation
- T1102 Web Service Command And Control
Weaknesses this control addresses (8)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-862 | Missing Authorization | 10,200+ | Missing authorization for internal functions is mitigated by requiring all external access to traverse managed boundaries. |
CWE-284 | Improper Access Control | 6,900+ | Boundary devices and interface controls directly enforce network-level access restrictions between spheres. |
CWE-863 | Incorrect Authorization | 3,900+ | Incorrect authorization decisions are enforced or detected at external and key internal managed interfaces. |
CWE-918 | Server-Side Request Forgery (SSRF) | 3,600+ | Outbound connections to external resources can be monitored and limited at the boundary, reducing SSRF impact. |
CWE-306 | Missing Authentication for Critical Function | 3,300+ | Public components are isolated in separate subnetworks and critical internal functions are reachable only via controlled interfaces. |
CWE-285 | Improper Authorization | 1,500+ | Communications are authorized only through managed boundary devices and segmented subnetworks. |
CWE-668 | Exposure of Resource to Wrong Sphere | 800+ | Internal resources are kept in separate network spheres from externally accessible components. |
CWE-923 | Improper Restriction of Communication Channel to Intended Endpoints | 69 | The control explicitly requires that all external connections use managed boundary devices that restrict channels to intended endpoints. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2025-55315 UPD | 9.4 | 9.9 | 0.6584 | partial |
CVE-2024-10264 UPD | 7.5 | 9.8 | 0.0094 | partial |
CVE-2024-22081 UPD | 7.4 | 9.8 | 0.0078 | partial |
CVE-2024-27922 UPD | 7.4 | 9.8 | 0.0082 | partial |
CVE-2026-41873 | 7.3 | 9.8 | 0.0044 | partial |
CVE-2026-13762 | 7.3 | 9.8 | 0.0044 | partial |
CVE-2026-13763 | 7.3 | 9.8 | 0.0047 | partial |
CVE-2026-57834 | 7.3 | 10.0 | 0.0034 | partial |
CVE-2026-58150 | 7.2 | 10.0 | 0.0032 | partial |
CVE-2026-23941 UPD | 7.1 | 9.4 | 0.0053 | partial |
CVE-2025-1867 UPD | 7.0 | 10.0 | 0.0037 | partial |
CVE-2026-2835 UPD | 7.0 | 9.1 | 0.0071 | partial |
CVE-2026-27690 | 7.0 | 9.1 | 0.0069 | partial |
CVE-2026-63382 | 7.0 | 9.2 | 0.0059 | partial |
CVE-2026-63385 | 7.0 | 9.2 | 0.0040 | partial |
CVE-2024-29643 UPD | 6.9 | 9.1 | 0.0055 | partial |
CVE-2025-43859 UPD | 6.9 | 9.1 | 0.0058 | partial |
CVE-2024-56523 UPD | 6.9 | 9.1 | 0.0057 | partial |
CVE-2026-2833 UPD | 6.9 | 9.1 | 0.0067 | partial |
CVE-2024-27185 UPD | 6.8 | 9.1 | 0.0044 | partial |
CVE-2023-29476 UPD | 6.8 | 9.1 | 0.0043 | partial |
CVE-2025-58068 UPD | 6.8 | 9.1 | 0.0039 | partial |
CVE-2025-12642 UPD | 6.8 | 9.1 | 0.0034 | partial |
CVE-2026-54387 UPD | 6.8 | 9.1 | 0.0044 | partial |
CVE-2026-54388 UPD | 6.8 | 9.1 | 0.0044 | partial |