πŸ•ΈοΈ Ada Research Browser

SC.md
← Back

SC β€” System & Communications Protection Domain Notes

CMMC Domain: SC (System & Communications Protection)
NIST 800-171 Family: 3.13.x


SC.L2-3.13.7 β€” SPLIT TUNNELING

Control: Prevent remote devices from simultaneously using non-remote connections with the system AND local unprotected connections.

Developer Debate

Practical Guidance


SC.L2-3.13.9 β€” CONNECTION TERMINATION

Control: Terminate network connections at end of session or after defined inactivity period.


SC General Notes

Encryption / FIPS

Firewall / Network Boundary

CUI in Email

SIEM Placement (In-Scope vs Supporting)

CUI Online Tools


SC.L2-3.13.11 β€” FIPS-VALIDATED CRYPTOGRAPHY (NEW DISCUSSION)

Control: Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.

Assessor Interpretation Challenges


RMM Tools as Security Protection Assets (SPAs) - LogMeIn Example

Context: Discussion on how Remote Monitoring and Management (RMM) tools interact with CUI environments for CMMC compliance.

SPA Classification Criteria