03.13: System and Communications Protection

Controls

03.13.01: Boundary Protection

Monitor and control communications at external managed interfaces to the system and key internal managed interfaces within the system. Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks. Connect to external systems only through managed interfaces that consist of boundary protection devices arranged in accordance with an organizational…

03.13.09: Network Disconnect

Terminate the network connection associated with a communications session at the end of the session or after [Assignment: organization-defined time period] of inactivity.

03.13.10: Cryptographic Key Establishment and Management

Establish and manage cryptographic keys in the system in accordance with the following key management requirements: [Assignment: organization-defined requirements for key generation, distribution, storage, access, and destruction].

03.13.11: Cryptographic Protection

Implement the following types of cryptography to protect the confidentiality of CUI: [Assignment: organization-defined types of cryptography].

03.13.12: Collaborative Computing Devices and Applications

Prohibit the remote activation of collaborative computing devices and applications with the following exceptions: [Assignment: organization-defined exceptions where remote activation is to be allowed]. Provide an explicit indication of use to users physically present at the devices.

03.13.13: Mobile Code

Define acceptable mobile code and mobile code technologies. Authorize, monitor, and control the use of mobile code.