Cyber Resilience

NIST 800-53 r5 · Controls catalogue · Family SC

SC-7Boundary Protection

Monitor and control communications at the external managed interfaces to the system and at key internal managed interfaces within the system; Implement subnetworks for publicly accessible system components that are {{ insert: param, sc-07_odp }} separated from internal organizational networks; and Connect to external networks or systems only through managed interfaces consisting of boundary protection devices arranged in accordance with an organizational security and privacy architecture.

Last updated: 22 August 2026 07:11 UTC

Implementations targeting this control (27)

ATT&CK techniques this control mitigates (156)

Weaknesses this control addresses (8)AI-assisted

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-862Missing Authorization10,200+Missing authorization for internal functions is mitigated by requiring all external access to traverse managed boundaries.
CWE-284Improper Access Control6,900+Boundary devices and interface controls directly enforce network-level access restrictions between spheres.
CWE-863Incorrect Authorization3,900+Incorrect authorization decisions are enforced or detected at external and key internal managed interfaces.
CWE-918Server-Side Request Forgery (SSRF)3,600+Outbound connections to external resources can be monitored and limited at the boundary, reducing SSRF impact.
CWE-306Missing Authentication for Critical Function3,300+Public components are isolated in separate subnetworks and critical internal functions are reachable only via controlled interfaces.
CWE-285Improper Authorization1,500+Communications are authorized only through managed boundary devices and segmented subnetworks.
CWE-668Exposure of Resource to Wrong Sphere800+Internal resources are kept in separate network spheres from externally accessible components.
CWE-923Improper Restriction of Communication Channel to Intended Endpoints69The control explicitly requires that all external connections use managed boundary devices that restrict channels to intended endpoints.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2025-55315 9.49.90.6584partial
CVE-2024-10264 7.59.80.0094partial
CVE-2024-22081 7.49.80.0078partial
CVE-2024-27922 7.49.80.0082partial
CVE-2026-418737.39.80.0044partial
CVE-2026-137627.39.80.0044partial
CVE-2026-137637.39.80.0047partial
CVE-2026-578347.310.00.0034partial
CVE-2026-581507.210.00.0032partial
CVE-2026-23941 7.19.40.0053partial
CVE-2025-1867 7.010.00.0037partial
CVE-2026-2835 7.09.10.0071partial
CVE-2026-276907.09.10.0069partial
CVE-2026-633827.09.20.0059partial
CVE-2026-633857.09.20.0040partial
CVE-2024-29643 6.99.10.0055partial
CVE-2025-43859 6.99.10.0058partial
CVE-2024-56523 6.99.10.0057partial
CVE-2026-2833 6.99.10.0067partial
CVE-2024-27185 6.89.10.0044partial
CVE-2023-29476 6.89.10.0043partial
CVE-2025-58068 6.89.10.0039partial
CVE-2025-12642 6.89.10.0034partial
CVE-2026-54387 6.89.10.0044partial
CVE-2026-54388 6.89.10.0044partial

Other controls in family SC

SC-1 SC-10 SC-11 SC-12 SC-13 SC-14 SC-15 SC-16 SC-17 SC-18 SC-19 SC-2 SC-20 SC-21 SC-22 SC-23 SC-24 SC-25 SC-26 SC-27 SC-28 SC-29 SC-3 SC-30 SC-31 SC-32 SC-33 SC-34 SC-35 SC-36 SC-37 SC-38 SC-39 SC-4 SC-40 SC-41 SC-42 SC-43 SC-44 SC-45 SC-46 SC-47 SC-48 SC-49 SC-5 SC-50 SC-51 SC-6 SC-8 SC-9