SI-8: Spam Protection
Control Family:
CSF v1.1 References:
Baselines:
Previous Version:
- NIST Special Publication 800-53 Revision 4:
- SI-8: Spam Protection
Control Statement
- Employ spam protection mechanisms at system entry and exit points to detect and act on unsolicited messages; and
- Update spam protection mechanisms when new releases are available in accordance with organizational configuration management policy and procedures.
Supplemental Guidance
System entry and exit points include firewalls, remote-access servers, electronic mail servers, web servers, proxy servers, workstations, notebook computers, and mobile devices. Spam can be transported by different means, including email, email attachments, and web accesses. Spam protection mechanisms include signature definitions.
OT Discussion
OT organizations implement spam protection by removing spam transport mechanisms, functions, and services (e.g., electronic mail, web browsing) from the OT. Rationale for removing SI-8 (2) from MOD and HIGH baselines: Spam transport mechanisms are disabled or removed from the OT, so automatic updates are not necessary.
Control Enhancements
SI-8(2): Automatic Updates
Baseline(s):
- Moderate
- High
Automatically update spam protection mechanisms [Assignment: organization-defined frequency].
SI-8(3): Continuous Learning Capability
Baseline(s):
Implement spam protection mechanisms with a learning capability to more effectively identify legitimate communications traffic.