Policy and Procedures SC-1
System and Communications Protection · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds SC-1 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, System and Communications Protection family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
SC-1 (Policy and Procedures) sits at the top of the SC (System and Communications Protection) family. It asks you to write down — and keep current — the policy and procedures that govern how this system protects its network boundaries and communications: the purpose, the scope, who is responsible, and how it all stays consistent with law and higher-level organizational rules. It is a documentation control, not a technical one, and it anchors every other SC control below it. It lives in the Low baseline.
What good looks like
- Write a short System and Communications Protection policy that states its purpose, scope, roles, responsibilities, and management commitment — and name the person accountable for it.
- Back the policy with procedures — the step-by-step of how the SC controls actually get done on this server, such as how the firewall and session timeouts are configured.
- Designate an official to own the policy and procedures and keep them current.
- Review and update both on a set schedule (for example, yearly) and after major changes — a new service, a re-platform, or an incident.
- Keep the policy consistent with applicable laws, regulations, and higher-level policy, and make sure the people who need it can find it.
Framework mapping
- NIST CSF 2.0 — GV.PO-01 — Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
How to move it toward Implemented
- Draft a one-page SC policy — purpose, scope, roles, the named owner, and a review cadence — and store it in version control or a documented location.
- Write the matching procedures as a checklist that points at the real configuration on this box (for example,
/etc/ssh/sshd_config, the firewall rules, and the TLS — Transport Layer Security — settings). - Record a review date on the document itself — a
Last reviewed:line and aNext review:date — and set a calendar reminder to match. - Attach the policy and procedures document as hardening evidence on the asset, naming
SC-1in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.