1Overview
SC.L2-3.13.1 opens the System and Communications Protection family with the boundary control that underlies the rest. It requires that communications be monitored, controlled, and protected at the external boundaries and key internal boundaries of organizational systems, so that the traffic entering, leaving, and crossing sensitive points inside the system is watched, governed, and safeguarded. It is a five-point requirement that cannot be deferred on a plan of action.
The boundary is where a system meets the outside world and where its more sensitive zones meet its less sensitive ones. This control requires three actions, monitoring, controlling, and protecting, applied at two kinds of boundary: the external boundary between the system and external networks, and the key internal boundaries between zones inside it. Establishing those boundaries first, then watching, governing, and safeguarding communications across them, is what makes a defended perimeter and defended interior possible. Its five-point weight reflects that the boundary is the primary line of network defense.
Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems.
The requirement combines three actions across two boundary types, and the eight assessment objectives spell out each combination plus the definition of the boundaries themselves. The external boundary and key internal boundaries must first be defined; then communications must be monitored, controlled, and protected at each. Monitoring watches the traffic, controlling governs what is allowed, and protecting safeguards it in transit. Covering all three at both the external and key internal boundaries is what the control requires.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.13.1 into eight objectives: define each boundary, then monitor, control, and protect communications at each.
The external system boundary is defined. Where the system meets external networks is established.
Key internal system boundaries are defined. The sensitive divisions inside the system are established.
Communications are monitored at the external boundary. External traffic is watched.
Communications are monitored at key internal boundaries. Internal boundary traffic is watched.
Communications are controlled at the external boundary. External traffic is governed.
Communications are controlled at key internal boundaries. Internal boundary traffic is governed.
Communications are protected at the external boundary. External traffic is safeguarded.
Communications are protected at key internal boundaries. Internal boundary traffic is safeguarded.
The eight objectives are the two boundary definitions and the three actions applied at each. The common gaps are the internal boundaries, objectives [b], [d], [f], and [h], which are often neglected in favor of the external perimeter, leaving the interior flat and unsegmented. The assessor looks for all three actions at both the external and key internal boundaries.
3Failure Patterns
The failures are about boundaries left undefined or undefended, especially internal ones.
Flat internal network
A defended external perimeter with no internal boundaries lets anything past the edge move freely inside. Defining and defending key internal boundaries segments the interior.
Monitoring without control
Watching boundary traffic without governing it sees problems but does not stop them. Control has to accompany monitoring at each boundary.
Boundaries undefined
Without defining the external and internal boundaries, there is no clear place to apply the three actions. Defining the boundaries is the basis for defending them.
4Ownership
This is an IT and network-owned technical control.
| Role | Responsibility for this control |
|---|---|
| Network and IT | Defines the boundaries and monitors, controls, and protects communications at each. Owns the boundary defense evidence. |
| Security or compliance lead | Confirms all three actions apply at both external and internal boundaries. |
| Program lead | Documents the boundaries in the system security plan and reviews coverage. |
5Tooling
The control is delivered by boundary protection devices and monitoring at external and internal boundaries.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a], [b] | Boundary definition and documentation | Defined external and key internal boundaries. |
| [c], [d] | Firewalls, IDS/IPS, traffic monitoring | Monitoring at both boundaries. |
| [e], [f] | Firewall rules, segmentation, ACLs | Control at both boundaries. |
| [g], [h] | Encryption, boundary protection | Protection at both boundaries. |
The caveat is that all three actions have to reach the internal boundaries, not just the external one. A firewall at the edge with a flat interior meets the external objectives but fails the internal ones. The assessor examines all eight, so both boundaries and all three actions have to hold.
6Evidence
The satisfied version of 3.13.1 shows defined boundaries defended on all three actions.
| Evidence | What it demonstrates |
|---|---|
| Boundary documentation and diagrams | Objectives [a], [b]. Defined boundaries. |
| Firewall and monitoring configuration | Objectives [c] through [h]. Communications monitored, controlled, and protected at both boundaries. |
The evidence should show defined external and internal boundaries with communications monitored, controlled, and protected at each. The boundary documentation together with the device configurations is the clearest demonstration, and because this control cannot sit on a plan of action, the defenses have to be real at the time of assessment.
A perimeter alone leaves a flat interior
The boundary is the primary line of network defense, and it includes the key internal boundaries as much as the external edge, so this five-point control asks that communications be monitored, controlled, and protected at both. Defining and defending those boundaries is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.13.1. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.13.1[a] through 3.13.1[h]. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing SC.L2-3.13.1 among the five-point basic security requirements. ecfr.gov