{"data":{"id":"SC-37","name":"Out-of-band Channels","family":"SC","family_name":"System and Communications Protection","withdrawn":false,"description":"Employ the following out-of-band channels for the physical delivery or electronic transmission of [Assignment: organization-defined information, system components, or devices] to [Assignment: organization-defined individuals or systems]: [Assignment: organization-defined out-of-band channels].","supplemental_guidance":"Out-of-band channels include local, non-network accesses to systems; network paths physically separate from network paths used for operational traffic; or non-electronic paths, such as the U.S. Postal Service. The use of out-of-band channels is contrasted with the use of in-band channels (i.e., the same channels) that carry routine operational traffic. Out-of-band channels do not have the same vulnerability or exposure as in-band channels. Therefore, the confidentiality, integrity, or availability compromises of in-band channels will not compromise or adversely affect the out-of-band channels. Organizations may employ out-of-band channels in the delivery or transmission of organizational items, including authenticators and credentials; cryptographic key management information; system and data backups; configuration management changes for hardware, firmware, or software; security updates; maintenance information; and malicious code protection updates. For example, cryptographic keys for encrypted files are delivered using a different channel than the file.","enhancements":[{"id":"SC-37(01)","name":"Ensure Delivery and Transmission","statement":"Employ [Assignment: organization-defined controls] to ensure that only [Assignment: organization-defined individuals or systems] receive the following information, system components, or devices: [Assignment: organization-defined information, system components, or devices].","baselines":[]}],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"nist_800_53":{"rev5":{"id":"SC-37","name":"Out-of-band Channels","description":"Employ the following out-of-band channels for the physical delivery or electronic transmission of [Assignment: organization-defined information, system components, or devices] to [Assignment: organization-defined individuals or systems]: [Assignment: organization-defined out-of-band channels].","discussion":"Out-of-band channels include local, non-network accesses to systems; network paths physically separate from network paths used for operational traffic; or non-electronic paths, such as the U.S. Postal Service. The use of out-of-band channels is contrasted with the use of in-band channels (i.e., the same channels) that carry routine operational traffic. Out-of-band channels do not have the same vulnerability or exposure as in-band channels. Therefore, the confidentiality, integrity, or availability compromises of in-band channels will not compromise or adversely affect the out-of-band channels. Organizations may employ out-of-band channels in the delivery or transmission of organizational items, including authenticators and credentials; cryptographic key management information; system and data backups; configuration management changes for hardware, firmware, or software; security updates; maintenance information; and malicious code protection updates. For example, cryptographic keys for encrypted files are delivered using a different channel than the file.","related_controls":["AC-02","CM-03","CM-05","CM-07","IA-02","IA-04","IA-05","MA-04","SC-12","SI-03","SI-04","SI-07"],"baseline_low":null,"baseline_moderate":null,"baseline_high":null,"baseline_privacy":null,"new_in_rev5":false,"changes_from_rev4":"No significant title changes from Rev 4."}},"compliance_mappings":{"iso_27001_2022":[],"iso_27002_2022":[],"cobit_2019":[],"pci_dss_v4":["8.3","8.4"],"nist_csf_2":[],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":["Art. 21(2)(j)"],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":[],"osfi_b13":[],"finma_circular":["IV.C(63)"],"gdpr":[],"dora":[],"bio2":[],"rbi_csf":["Annex1.4"],"fisc":[],"lgpd_bcb":[],"hkma_tme1":["TME1.10.4"],"mlps_2":[],"dnb_good_practice":[],"cra":[],"swift_cscf":[],"qatar_nia":["CS"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":[],"iso_27799":[],"lloyds_ms":[],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1071","name":"Application Layer Protocol","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Out-of-band channels for delivering critical security updates and cryptographic material ensure that adversaries controlling in-band application layer protocols cannot intercept or tamper with these sensitive transmissions."},{"id":"T1114","name":"Email Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Using out-of-band channels for transmitting sensitive organizational information reduces the value of email collection by ensuring that the most critical data does not traverse compromisable email systems."},{"id":"T1213","name":"Data from Information Repositories","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Transmitting sensitive data through out-of-band channels rather than information repositories ensures that adversaries who compromise wikis or document stores cannot access the most critical organizational data."},{"id":"T1489","name":"Service Stop","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Out-of-band management channels ensure that administrative access to critical services is maintained even when adversaries stop primary communication services, enabling recovery operations."},{"id":"T1071.001","name":"Web Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Delivering sensitive configuration and credential material through out-of-band channels rather than web protocols ensures adversaries monitoring HTTP/HTTPS traffic cannot intercept these transmissions."},{"id":"T1071.002","name":"File Transfer Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Using out-of-band delivery for sensitive files rather than FTP ensures that adversaries monitoring file transfer protocols cannot intercept critical data transmissions."},{"id":"T1071.003","name":"Mail Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Transmitting authentication credentials and cryptographic keys through out-of-band channels rather than email protocols prevents adversaries monitoring mail traffic from capturing this sensitive material."},{"id":"T1071.004","name":"DNS","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Using out-of-band channels for DNS configuration and key material delivery prevents adversaries who have compromised DNS resolution from intercepting or manipulating these critical updates."},{"id":"T1114.001","name":"Local Email Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Ensuring sensitive communications are delivered through out-of-band channels rather than stored in local email clients reduces the value of local email collection to adversaries."},{"id":"T1114.002","name":"Remote Email Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Using out-of-band channels for critical communications ensures that adversaries collecting email remotely through protocol exploitation cannot access the most sensitive organizational information."},{"id":"T1114.003","name":"Email Forwarding Rule","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Delivering critical information through out-of-band channels renders email forwarding rules ineffective for capturing sensitive data, as the most valuable communications bypass email entirely."},{"id":"T1213.005","name":"Messaging Applications","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Transmitting sensitive communications through out-of-band channels rather than organizational messaging applications ensures adversaries monitoring Slack, Teams, or similar platforms cannot intercept critical information."}],"metadata":{"last_reviewed":"2026-02-19","review_notes":"","mapping_status":"complete"},"function":"preventative","used_by_patterns":[]}}