{
  "node_id": "nist-800-53-sc7",
  "title": "Boundary Protection (NIST 800-53)",
  "domain": "Cybersecurity",
  "version": "1.1.1",
  "last_updated": "2026-04-30",
  "bluf": "NIST SP 800-53 Rev 5 Control SC-7 (Boundary Protection) requires organizations to monitor and control communications at the external boundary of the system and at key internal boundaries, implement subnetworks for publicly accessible system components, and connect to external networks or systems only through managed interfaces consisting of boundary protection devices arranged in accordance with an organizational security and privacy architecture. SC-7 is a HIGH baseline control mandatory for all federal systems at MODERATE and HIGH impact levels, FedRAMP High/Moderate, and CMMC 2.0 Level 2, and it is the foundational network security control upon which egress filtering, intrusion detection, and data loss prevention depend. For AI agent deployments, SC-7 is critical because AI agents executing tool calls and API invocations create dynamic outbound network flows that can exfiltrate data, communicate with attacker-controlled infrastructure, or access unauthorized external services - SC-7 egress controls must explicitly govern which external endpoints AI agents are permitted to connect to, and any agent connection attempt to an unapproved endpoint must be blocked and alerted.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "ai_overlay_2026",
      "industry_mapping"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "fips-199-security-categorization",
    "nist-sp-800-39-managing-information-security-risk",
    "nist-sp-800-41-r1-firewalls",
    "nist-sp-800-53-r5",
    "nist-sp-800-207"
  ],
  "primary_citations_count": 6
}