DKDavid Koran& Associates
Home The CMMC Guide Part III · System and Communications Protection SC.L2-3.13.1
The CMMC Guide · System and Communications Protection Family

SC.L2-3.13.1  Monitor and Control Communications

Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems.

Family
System and Communications ProtectionSC, 16 requirements
Point Value
5Highest weight in the methodology
POA&M Eligible
NoCannot remain open at assessment
Objectives
EightPer NIST SP 800-171A

1Overview

SC.L2-3.13.1 opens the System and Communications Protection family with the boundary control that underlies the rest. It requires that communications be monitored, controlled, and protected at the external boundaries and key internal boundaries of organizational systems, so that the traffic entering, leaving, and crossing sensitive points inside the system is watched, governed, and safeguarded. It is a five-point requirement that cannot be deferred on a plan of action.

The boundary is where a system meets the outside world and where its more sensitive zones meet its less sensitive ones. This control requires three actions, monitoring, controlling, and protecting, applied at two kinds of boundary: the external boundary between the system and external networks, and the key internal boundaries between zones inside it. Establishing those boundaries first, then watching, governing, and safeguarding communications across them, is what makes a defended perimeter and defended interior possible. Its five-point weight reflects that the boundary is the primary line of network defense.

The requirement · NIST SP 800-171 Rev 2, 3.13.1

Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems.

The requirement combines three actions across two boundary types, and the eight assessment objectives spell out each combination plus the definition of the boundaries themselves. The external boundary and key internal boundaries must first be defined; then communications must be monitored, controlled, and protected at each. Monitoring watches the traffic, controlling governs what is allowed, and protecting safeguards it in transit. Covering all three at both the external and key internal boundaries is what the control requires.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.13.1 into eight objectives: define each boundary, then monitor, control, and protect communications at each.

[a]

The external system boundary is defined. Where the system meets external networks is established.

MeetsThe external system boundary is defined.
FailsThe external boundary is undefined.
[b]

Key internal system boundaries are defined. The sensitive divisions inside the system are established.

MeetsKey internal boundaries are defined.
FailsNo internal boundaries are identified.
[c]

Communications are monitored at the external boundary. External traffic is watched.

MeetsCommunications are monitored at the external boundary.
FailsExternal traffic is unmonitored.
[d]

Communications are monitored at key internal boundaries. Internal boundary traffic is watched.

MeetsCommunications are monitored at key internal boundaries.
FailsInternal boundary traffic is unmonitored.
[e]

Communications are controlled at the external boundary. External traffic is governed.

MeetsCommunications are controlled at the external boundary.
FailsExternal traffic is uncontrolled.
[f]

Communications are controlled at key internal boundaries. Internal boundary traffic is governed.

MeetsCommunications are controlled at key internal boundaries.
FailsInternal boundary traffic is uncontrolled.
[g]

Communications are protected at the external boundary. External traffic is safeguarded.

MeetsCommunications are protected at the external boundary.
FailsExternal traffic is unprotected.
[h]

Communications are protected at key internal boundaries. Internal boundary traffic is safeguarded.

MeetsCommunications are protected at key internal boundaries.
FailsInternal boundary traffic is unprotected.

The eight objectives are the two boundary definitions and the three actions applied at each. The common gaps are the internal boundaries, objectives [b], [d], [f], and [h], which are often neglected in favor of the external perimeter, leaving the interior flat and unsegmented. The assessor looks for all three actions at both the external and key internal boundaries.

3Failure Patterns

The failures are about boundaries left undefined or undefended, especially internal ones.

Flat internal network

A defended external perimeter with no internal boundaries lets anything past the edge move freely inside. Defining and defending key internal boundaries segments the interior.

Monitoring without control

Watching boundary traffic without governing it sees problems but does not stop them. Control has to accompany monitoring at each boundary.

Boundaries undefined

Without defining the external and internal boundaries, there is no clear place to apply the three actions. Defining the boundaries is the basis for defending them.

The common root
This control fails when the boundary is imagined as only the outer edge. Defense that stops at the perimeter leaves a flat interior where a single foothold reaches everything, so the key internal boundaries matter as much as the external one. Monitoring, controlling, and protecting at both is what gives the system depth.

4Ownership

This is an IT and network-owned technical control.

RoleResponsibility for this control
Network and ITDefines the boundaries and monitors, controls, and protects communications at each. Owns the boundary defense evidence.
Security or compliance leadConfirms all three actions apply at both external and internal boundaries.
Program leadDocuments the boundaries in the system security plan and reviews coverage.
See also: This control is the foundation of the family, working with the deny-by-default rule of SC.L2-3.13.6 and the public-access separation of SC.L2-3.13.5.

5Tooling

The control is delivered by boundary protection devices and monitoring at external and internal boundaries.

ObjectivesToolingWhat it provides
[a], [b]Boundary definition and documentationDefined external and key internal boundaries.
[c], [d]Firewalls, IDS/IPS, traffic monitoringMonitoring at both boundaries.
[e], [f]Firewall rules, segmentation, ACLsControl at both boundaries.
[g], [h]Encryption, boundary protectionProtection at both boundaries.

The caveat is that all three actions have to reach the internal boundaries, not just the external one. A firewall at the edge with a flat interior meets the external objectives but fails the internal ones. The assessor examines all eight, so both boundaries and all three actions have to hold.

6Evidence

The satisfied version of 3.13.1 shows defined boundaries defended on all three actions.

EvidenceWhat it demonstrates
Boundary documentation and diagramsObjectives [a], [b]. Defined boundaries.
Firewall and monitoring configurationObjectives [c] through [h]. Communications monitored, controlled, and protected at both boundaries.

The evidence should show defined external and internal boundaries with communications monitored, controlled, and protected at each. The boundary documentation together with the device configurations is the clearest demonstration, and because this control cannot sit on a plan of action, the defenses have to be real at the time of assessment.

A perimeter alone leaves a flat interior

The boundary is the primary line of network defense, and it includes the key internal boundaries as much as the external edge, so this five-point control asks that communications be monitored, controlled, and protected at both. Defining and defending those boundaries is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.13.1. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.13.1[a] through 3.13.1[h]. csrc.nist.gov
  3. 32 CFR 170.24, CMMC Scoring Methodology, listing SC.L2-3.13.1 among the five-point basic security requirements. ecfr.gov
← Previous: Security Assessment
CA.L2-3.12.4 · System Security Plan
Next in System and Communications Protection →
SC.L2-3.13.2 · Security Engineering Principles
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry SC.L2-3.13.1 · Edition 2026.1 · Last reviewed July 12, 2026