SC-37 Out-of-band Channels

System and Communications Protection

Description

Employ the following out-of-band channels for the physical delivery or electronic transmission of [Assignment: organization-defined parameters] to [Assignment: organization-defined parameters]: [Assignment: organization-defined parameters].

Supplemental Guidance

Out-of-band channels include local, non-network accesses to systems; network paths physically separate from network paths used for operational traffic; or non-electronic paths, such as the U.S. Postal Service. The use of out-of-band channels is contrasted with the use of in-band channels (i.e., the same channels) that carry routine operational traffic. Out-of-band channels do not have the same vulnerability or exposure as in-band channels. Therefore, the confidentiality, integrity, or availability compromises of in-band channels will not compromise or adversely affect the out-of-band channels. Organizations may employ out-of-band channels in the delivery or transmission of organizational items, including authenticators and credentials; cryptographic key management information; system and data backups; configuration management changes for hardware, firmware, or software; security updates; maintenance information; and malicious code protection updates. For example, cryptographic keys for encrypted files are delivered using a different channel than the file.

Changes from Rev 4

No significant title changes from Rev 4.

Compliance Mappings

PCI DSS v4.0.1

8.38.4

NIS2 Directive

Art. 21(2)(j)

FINMA Circular 2023/1

IV.C(63)

RBI CSF

Annex1.4

HKMA TM-E-1

TME1.10.4

Qatar NIA

CS