NIST SP 800-53 Rev. 5 · System and Communications Protection

SC-7 — Boundary Protection

Unrestricted inbound exposure without approval. Published queries for three platforms, each with the evidence it needs and the limits of what it shows.

Why this matters

A server left open to the entire internet without approval

Cloud systems make it trivial to open a service to the whole internet, often as a temporary measure during troubleshooting. Temporary frequently becomes permanent. Some public exposure is intended and legitimate, so a check that reports every open port is ignored within a week.

Why this check earns its place. It distinguishes deliberate, documented exposure from undocumented exposure, which is the distinction that makes the result actionable rather than noise.

What it reads
The organization's own firewall rules, compared against its register of approved exposures.
What it reports
Services reachable from anywhere on the internet with no unexpired approval on record.

See related public disclosures on the Signals page →

The requirement

The organization must monitor and control communications at the external managed interfaces to the system, and connect to external networks only through managed interfaces consisting of boundary protection devices arranged in accordance with an organizational security architecture.

NIST SP 800-53 Rev. 5 — SC-7 (Boundary Protection).

NIST requires controlled external interfaces. Which exposures are acceptable, for how long, and with what compensating controls is organization-defined — supplied here through the approved exposure register. Public exposure is not automatically wrong; undocumented or expired exposure is.

What a check finds

Inbound rule permitting unrestricted source access with no current, unexpired entry in the approved exposure register.

Choose your platform

CISA performance goals

  • 3.S — Secure internet-facing devices
  • 3.I — Implement logical/physical network segmentation

Full coverage map →

What a result does not prove

Unrestricted exposure is not automatically a vulnerability — public web tiers are meant to be public. What this check establishes is that the exposure is not currently covered by a documented, unexpired approval.