1Overview
SC.L2-3.13.13 governs mobile code, the executable content that runs from web pages and documents. It requires that the use of mobile code be controlled and monitored, so that scripts and applets that execute on organizational systems are governed rather than allowed to run freely. It is a one-point requirement and may be deferred on a plan of action.
Mobile code, JavaScript, ActiveX, Java applets, macros, and similar, executes on a system without being installed there, arriving through web pages, email, and documents. Because it runs automatically and comes from outside, it is a common delivery path for malicious activity. This control requires that its use be controlled, governed by what is permitted and how, and monitored, so that its execution is observed. The two assessment objectives are controlling and monitoring the use of mobile code.
Control and monitor the use of mobile code.
The requirement pairs control and monitoring for mobile code. Controlling its use means governing which mobile code is permitted and restricting or disabling what is not, through browser and application settings and policy. Monitoring its use means observing mobile code execution so that misuse or malicious code can be detected. Together they keep this automatic, externally sourced code from running unchecked.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.13.13 into two objectives: control and monitor the use of mobile code.
The use of mobile code is controlled. Which mobile code runs, and how, is governed.
The use of mobile code is monitored. Mobile code execution is observed.
The two objectives are control and monitoring. The common gap is at objective [b], where mobile code is restricted by configuration but its use is not actually monitored. The assessor looks for both control and monitoring of mobile code.
3Failure Patterns
The failures are about mobile code running unchecked.
Uncontrolled execution
Where any mobile code runs freely, malicious scripts and applets execute along with legitimate ones. Controlling use governs what is permitted.
Control without monitoring
Restricting mobile code by configuration without monitoring its use misses attempts and anomalies. Monitoring completes the control.
Inconsistent across applications
Governing mobile code in the browser but not in document applications leaves paths open. Control and monitoring have to cover the ways mobile code runs.
4Ownership
This is an IT and security-owned control.
| Role | Responsibility for this control |
|---|---|
| IT and security | Controls and monitors mobile code through configuration and monitoring. Owns the evidence. |
| System administrator | Applies browser and application settings governing mobile code. |
| Security or compliance lead | Confirms mobile code use is both controlled and monitored. |
5Tooling
The control is delivered by browser and application configuration and monitoring.
| Objective | Tooling | What it provides |
|---|---|---|
| [a] | Browser and application mobile-code settings | Controlled use of mobile code. |
| [b] | Endpoint and web monitoring | Monitored use of mobile code. |
The caveat is that both control and monitoring have to be present, across the ways mobile code runs. Configuration alone without monitoring, or coverage of the browser but not documents, leaves gaps. The assessor examines control and monitoring, so both objectives have to hold.
6Evidence
The satisfied version of 3.13.13 shows mobile code controlled and monitored.
| Evidence | What it demonstrates |
|---|---|
| Mobile-code configuration | Objective [a]. Use controlled. |
| Monitoring records | Objective [b]. Use monitored. |
The evidence should show the use of mobile code controlled through configuration and monitored. The mobile-code configuration together with the monitoring records is the clearest demonstration of the control.
Code that runs automatically should be governed
Mobile code executes from web pages and documents without being installed, a common path for malicious activity, so this control asks that its use be controlled and monitored. Governing and observing mobile code is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.13.13. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.13.13[a] and 3.13.13[b]. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov