Organizational Control: Mobile Code
Control ID: SC-18 Mobile Code | Family: System and Communications Protection | Source: NIST 800-53r4 |
Control: The organization:
|
||
Supplemental Guidance: Decisions regarding the employment of mobile code within organizational information systems are based on the potential for the code to cause damage to the systems if used maliciously. Mobile code technologies include, for example, Java, JavaScript, ActiveX, Postscript, PDF, Shockwave movies, Flash animations, and VBScript. Usage restrictions and implementation guidance apply to both the selection and use of mobile code installed on servers and mobile code downloaded and executed on individual workstations and devices (e.g., smart phones). Mobile code policy and procedures address preventing the development, acquisition, or introduction of unacceptable mobile code within organizational information systems. Related Controls: AU-2, AU-12, CM-2, CM-6, SI-3 |
||
Control Enhancements: N/A | ||
References: NIST Special Publication 800-28; DoD Instruction 8552.01. | ||
Mechanisms: | ||
Protocol Implementation Conformance Statements: N/A |