DKDavid Koran& Associates
Home The CMMC Guide Part III · System and Communications Protection SC.L2-3.13.13
The CMMC Guide · System and Communications Protection Family

SC.L2-3.13.13  Control and Monitor Mobile Code

Control and monitor the use of mobile code.

Family
System and Communications ProtectionSC, 16 requirements
Point Value
1Lower weight, but not POA&M exempt
POA&M Eligible
YesOne-point requirement, may be deferred
Objectives
TwoPer NIST SP 800-171A

1Overview

SC.L2-3.13.13 governs mobile code, the executable content that runs from web pages and documents. It requires that the use of mobile code be controlled and monitored, so that scripts and applets that execute on organizational systems are governed rather than allowed to run freely. It is a one-point requirement and may be deferred on a plan of action.

Mobile code, JavaScript, ActiveX, Java applets, macros, and similar, executes on a system without being installed there, arriving through web pages, email, and documents. Because it runs automatically and comes from outside, it is a common delivery path for malicious activity. This control requires that its use be controlled, governed by what is permitted and how, and monitored, so that its execution is observed. The two assessment objectives are controlling and monitoring the use of mobile code.

The requirement · NIST SP 800-171 Rev 2, 3.13.13

Control and monitor the use of mobile code.

The requirement pairs control and monitoring for mobile code. Controlling its use means governing which mobile code is permitted and restricting or disabling what is not, through browser and application settings and policy. Monitoring its use means observing mobile code execution so that misuse or malicious code can be detected. Together they keep this automatic, externally sourced code from running unchecked.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.13.13 into two objectives: control and monitor the use of mobile code.

[a]

The use of mobile code is controlled. Which mobile code runs, and how, is governed.

MeetsThe use of mobile code is controlled through policy and configuration.
FailsMobile code runs without control.
[b]

The use of mobile code is monitored. Mobile code execution is observed.

MeetsThe use of mobile code is monitored.
FailsMobile code execution is unmonitored.

The two objectives are control and monitoring. The common gap is at objective [b], where mobile code is restricted by configuration but its use is not actually monitored. The assessor looks for both control and monitoring of mobile code.

3Failure Patterns

The failures are about mobile code running unchecked.

Uncontrolled execution

Where any mobile code runs freely, malicious scripts and applets execute along with legitimate ones. Controlling use governs what is permitted.

Control without monitoring

Restricting mobile code by configuration without monitoring its use misses attempts and anomalies. Monitoring completes the control.

Inconsistent across applications

Governing mobile code in the browser but not in document applications leaves paths open. Control and monitoring have to cover the ways mobile code runs.

The common root
This control fails because mobile code is invisible and automatic. It runs as a normal part of using the web and documents, so its execution is easy to overlook, yet that same automatic execution is what attackers exploit. Controlling and monitoring its use is what brings this quiet code under governance.

4Ownership

This is an IT and security-owned control.

RoleResponsibility for this control
IT and securityControls and monitors mobile code through configuration and monitoring. Owns the evidence.
System administratorApplies browser and application settings governing mobile code.
Security or compliance leadConfirms mobile code use is both controlled and monitored.
See also: This control complements the malicious code protection of the system and information integrity family and the collaborative device controls of SC.L2-3.13.12.

5Tooling

The control is delivered by browser and application configuration and monitoring.

ObjectiveToolingWhat it provides
[a]Browser and application mobile-code settingsControlled use of mobile code.
[b]Endpoint and web monitoringMonitored use of mobile code.

The caveat is that both control and monitoring have to be present, across the ways mobile code runs. Configuration alone without monitoring, or coverage of the browser but not documents, leaves gaps. The assessor examines control and monitoring, so both objectives have to hold.

6Evidence

The satisfied version of 3.13.13 shows mobile code controlled and monitored.

EvidenceWhat it demonstrates
Mobile-code configurationObjective [a]. Use controlled.
Monitoring recordsObjective [b]. Use monitored.

The evidence should show the use of mobile code controlled through configuration and monitored. The mobile-code configuration together with the monitoring records is the clearest demonstration of the control.

Code that runs automatically should be governed

Mobile code executes from web pages and documents without being installed, a common path for malicious activity, so this control asks that its use be controlled and monitored. Governing and observing mobile code is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.13.13. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.13.13[a] and 3.13.13[b]. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in System and Communications Protection
SC.L2-3.13.12 · Control Collaborative Computing Devices
Next in System and Communications Protection →
SC.L2-3.13.14 · Control and Monitor VoIP
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry SC.L2-3.13.13 · Edition 2026.1 · Last reviewed July 12, 2026