STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← All Controls

SC-37

System and Communications ProtectionRev 5organization

Out-of-Band Channels

Control Statement

Employ the following out-of-band channels for the physical delivery or electronic transmission of [Assignment: information, system components, or devices] to [Assignment: individuals or systems]: [Assignment: out-of-band channels].

Supplemental Guidance

Out-of-band channels include local, non-network accesses to systems; network paths physically separate from network paths used for operational traffic; or non-electronic paths, such as the U.S. Postal Service. The use of out-of-band channels is contrasted with the use of in-band channels (i.e., the same channels) that carry routine operational traffic. Out-of-band channels do not have the same vulnerability or exposure as in-band channels. Therefore, the confidentiality, integrity, or availability compromises of in-band channels will not compromise or adversely affect the out-of-band channels. Organizations may employ out-of-band channels in the delivery or transmission of organizational items, including authenticators and credentials; cryptographic key management information; system and data backups; configuration management changes for hardware, firmware, or software; security updates; maintenance information; and malicious code protection updates. For example, cryptographic keys for encrypted files are delivered using a different channel than the file.

Related Controls (12)

AC-2CM-3CM-5CM-7IA-2IA-4IA-5MA-4SC-12SI-3SI-4SI-7

CCI Identifiers (4)

CCI-002521Defines the out-of-band channels to be employed for the physical delivery or electronic transmission of organization-defined information, system components, or devices.CCI-002522Defines the information, system components, or devices that are to be electronically transmitted or physically delivered via organization-defined out-of-band channels.CCI-002524Employ organization-defined out-of-band channels for the physical delivery or electronic transmission of organization-defined information, system components, or devices to organization-defined individuals or systems.CCI-003599The organization defines the individuals or information systems to be the only recipients of organization-defined information, information system components, or devices, by employing organization-defined security safeguards.

Linked STIG Checks (0)

No STIG checks reference this control.