{"data":{"id":"SC-43","name":"Usage Restrictions","family":"SC","family_name":"System and Communications Protection","withdrawn":false,"description":"a. Establish usage restrictions and implementation guidelines for the following system components: [Assignment: organization-defined system components]; and\nb. Authorize, monitor, and control the use of such components within the system.","supplemental_guidance":"Usage restrictions apply to all system components including but not limited to mobile code, mobile devices, wireless access, and wired and wireless peripheral components (e.g., copiers, printers, scanners, optical devices, and other similar technologies). The usage restrictions and implementation guidelines are based on the potential for system components to cause damage to the system and help to ensure that only authorized system use occurs.","enhancements":[],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"nist_800_53":{"rev5":{"id":"SC-43","name":"Usage Restrictions","description":"a. Establish usage restrictions and implementation guidelines for the following system components: [Assignment: organization-defined system components]; and\nb. Authorize, monitor, and control the use of such components within the system.","discussion":"Usage restrictions apply to all system components including but not limited to mobile code, mobile devices, wireless access, and wired and wireless peripheral components (e.g., copiers, printers, scanners, optical devices, and other similar technologies). The usage restrictions and implementation guidelines are based on the potential for system components to cause damage to the system and help to ensure that only authorized system use occurs.","related_controls":["AC-18","AC-19","CM-06","SC-07","SC-18"],"baseline_low":null,"baseline_moderate":null,"baseline_high":null,"baseline_privacy":null,"new_in_rev5":false,"changes_from_rev4":"No significant title changes from Rev 4."}},"compliance_mappings":{"iso_27001_2022":[],"iso_27002_2022":[],"cobit_2019":[],"pci_dss_v4":[],"nist_csf_2":["PR.DS-01","PR.DS-02","PR.DS-10"],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":[],"osfi_b13":[],"finma_circular":[],"gdpr":[],"dora":[],"bio2":[],"rbi_csf":["Annex1.12"],"fisc":[],"lgpd_bcb":[],"hkma_tme1":[],"mlps_2":[],"dnb_good_practice":[],"cra":[],"swift_cscf":[],"sama_csf":["3.8"],"bom_ctrm":["3.12"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":[],"iso_27799":[],"lloyds_ms":[],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1011","name":"Exfiltration Over Other Network Medium","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Usage restrictions on network interfaces define which physical and wireless networks can be used for data transfer, preventing adversaries from exfiltrating data through unauthorized network media."},{"id":"T1078","name":"Valid Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Usage restrictions on authenticated sessions define permitted access times, locations, and device types, limiting adversary ability to exploit valid credentials outside approved usage parameters."},{"id":"T1613","name":"Container and Resource Discovery","tactics":["discovery"],"mapping_type":"mitigates","mapping_rationale":"Usage restrictions on container orchestration interfaces limit when and how container discovery operations can be performed, preventing adversaries from enumerating cluster resources outside approved contexts."},{"id":"T1078.004","name":"Cloud Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Usage restrictions on cloud accounts enforce conditional access policies including permitted IP ranges, device compliance, and session duration limits that constrain adversary use of compromised cloud credentials."},{"id":"T1114.003","name":"Email Forwarding Rule","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Usage restrictions on email forwarding rules define approved forwarding destinations and require administrative approval, preventing adversaries from creating unauthorized rules that exfiltrate email to external addresses."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: nist_csf_2 PR.DS-01, PR.DS-02, PR.DS-10 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"preventative","used_by_patterns":[]}}