03.13: System and Communications Protection
Controls
03.13.01: Boundary Protection
Monitor and control communications at external managed interfaces to the system and key internal managed interfaces within the system. Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks. Connect to external systems only through managed interfaces that consist of boundary protection devices arranged in accordance with an organizational…
03.13.04: Information in Shared System Resources
Prevent unauthorized and unintended information transfer via shared system resources.
03.13.06: Network Communications — Deny by Default — Allow by Exception
Deny network communications traffic by default, and allow network communications traffic by exception.
03.13.08: Transmission and Storage Confidentiality
Implement cryptographic mechanisms to prevent the unauthorized disclosure of CUI during transmission and while in storage.
03.13.09: Network Disconnect
Terminate the network connection associated with a communications session at the end of the session or after [Assignment: organization-defined time period] of inactivity.
03.13.10: Cryptographic Key Establishment and Management
Establish and manage cryptographic keys in the system in accordance with the following key management requirements: [Assignment: organization-defined requirements for key generation, distribution, storage, access, and destruction].
03.13.11: Cryptographic Protection
Implement the following types of cryptography to protect the confidentiality of CUI: [Assignment: organization-defined types of cryptography].
03.13.12: Collaborative Computing Devices and Applications
Prohibit the remote activation of collaborative computing devices and applications with the following exceptions: [Assignment: organization-defined exceptions where remote activation is to be allowed]. Provide an explicit indication of use to users physically present at the devices.
03.13.13: Mobile Code
Define acceptable mobile code and mobile code technologies. Authorize, monitor, and control the use of mobile code.
03.13.15: Session Authenticity
Protect the authenticity of communications sessions.