NIST SP 800-53 Rev. 5 · System and Communications Protection
SC-7 — Boundary Protection
Unrestricted inbound exposure without approval. Published queries for three platforms, each with the evidence it needs and the limits of what it shows.
Why this matters
A server left open to the entire internet without approval
Cloud systems make it trivial to open a service to the whole internet, often as a temporary measure during troubleshooting. Temporary frequently becomes permanent. Some public exposure is intended and legitimate, so a check that reports every open port is ignored within a week.
Why this check earns its place. It distinguishes deliberate, documented exposure from undocumented exposure, which is the distinction that makes the result actionable rather than noise.
- What it reads
- The organization's own firewall rules, compared against its register of approved exposures.
- What it reports
- Services reachable from anywhere on the internet with no unexpired approval on record.
See related public disclosures on the Signals page →
The requirement
The organization must monitor and control communications at the external managed interfaces to the system, and connect to external networks only through managed interfaces consisting of boundary protection devices arranged in accordance with an organizational security architecture.
NIST SP 800-53 Rev. 5 — SC-7 (Boundary Protection).
NIST requires controlled external interfaces. Which exposures are acceptable, for how long, and with what compensating controls is organization-defined — supplied here through the approved exposure register. Public exposure is not automatically wrong; undocumented or expired exposure is.
What a check finds
Inbound rule permitting unrestricted source access with no current, unexpired entry in the approved exposure register.
Choose your platform
CISA performance goals
- 3.S — Secure internet-facing devices
- 3.I — Implement logical/physical network segmentation
What a result does not prove
Unrestricted exposure is not automatically a vulnerability — public web tiers are meant to be public. What this check establishes is that the exposure is not currently covered by a documented, unexpired approval.