Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
3.13.13OFFICIAL STATEMENT BELOWDERIVED REQUIREMENTPENDING NIST SME REVIEW

3.13.13Mobile code control

3.13 System and Communications Protection · NIST SP 800-171 Rev. 2 · The heading label is this site's navigational shorthand; the official language is the statement below.

Independent interpretation

What this requirement is after

Mobile code — scripts and executable content that arrives and runs, from browser scripts to Office macros to script payloads in email — runs under policy, not by default. Internet-sourced macros are the canonical small-business breach vector this requirement points at.

Mapped practices

Brilliant at the Basics practices that support this requirement

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Block internet-sourced macros and restrict script execution by policy; modern platform defaults help, but verify they are enforced rather than assumed.
  • Define which mobile-code technologies are acceptable and where; 'monitor' means logs or reports someone can actually produce, not an intention.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • Policy exports for macro and script restrictions
  • Reports showing blocked or allowed mobile-code events for a sampled period
Artifacts

Templates and worksheets with a mapped relationship

No artifact in the library names this requirement yet. The library index groups everything by category and practice.

The other revision

Where this lands in Rev. 3

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated