# SC-37 Out-of-band Channels

NIST SP 800-53 control. Family: SC System and Communications Protection. Function: preventative. In no baseline. Mapping licence: CC BY-SA 4.0.

Statement: Employ the following out-of-band channels for the physical delivery or electronic transmission of [Assignment: organization-defined information, system components, or devices] to [Assignment: organization-defined individuals or systems]: [Assignment: organization-defined out-of-band channels].
Guidance: Out-of-band channels include local, non-network accesses to systems; network paths physically separate from network paths used for operational traffic; or non-electronic paths, such as the U.S. Postal Service. The use of out-of-band channels is contrasted with the use of in-band channels (i.e., the same channels) that carry routine operational traffic. Out-of-band channels do not have the same vulnerability or exposure as in-band channels. Therefore, the confidentiality, integrity, or availability compromises of in-band channels will not compromise or adversely affect the out-of-band channels. Organizations may employ out-of-band channels in the delivery or transmission of organizational items, including authenticators and credentials; cryptographic key management information; system and data backups; configuration management changes for hardware, firmware, or software; security updates; maintenance information; and malicious code protection updates. For example, cryptographic keys for encrypted files are delivered using a different channel than the file.

## Enhancements (1)
- SC-37(01) Ensure Delivery and Transmission
Each enhancement's statement: /api/v1/controls/SC-37?fields=enhancements

## Clauses by framework (6 frameworks)
- pci_dss_v4: 8.3, 8.4
- nis2: Art. 21(2)(j)
- finma_circular: IV.C(63)
- rbi_csf: Annex1.4
- hkma_tme1: TME1.10.4
- qatar_nia: CS

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/SC-37
- Clauses only: /api/v1/controls/SC-37?fields=mappings
- Page for people: /controls/sc-37/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
