STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← All Controls

SC-7 (9)

System and Communications ProtectionRev 5system

Restrict Threatening Outgoing Communications Traffic

Control Statement

(a) Detect and deny outgoing communications traffic posing a threat to external systems; and (b) Audit the identity of internal users associated with denied communications.

Supplemental Guidance

Detecting outgoing communications traffic from internal actions that may pose threats to external systems is known as extrusion detection. Extrusion detection is carried out within the system at managed interfaces. Extrusion detection includes the analysis of incoming and outgoing communications traffic while searching for indications of internal threats to the security of external systems. Internal threats to external systems include traffic indicative of denial-of-service attacks, traffic with spoofed source addresses, and traffic that contains malicious code. Organizations have criteria to determine, update, and manage identified threats related to extrusion detection.

Related Controls (7)

AU-2AU-6SC-5SC-38SC-44SI-3SI-4

CCI Identifiers (4)

CCI-002399Deny outgoing communications traffic posing a threat to external systems.CCI-002400Audit the identity of internal users associated with denied outgoing communications traffic posing a threat to external systems.CCI-002398Detect outgoing communications traffic posing a threat to external systems.CCI-001115The information system, at managed interfaces, denies network traffic and audits internal users (or malicious code) posing a threat to external information systems.

Linked STIG Checks (9)

Across 8 STIGs. Click to expand.