# SC-35 — External Malicious Code Identification

- **Control ID:** SC-35
- **Family:** [SC](/md/families/SC.md)
- **Baselines:** No content available.
- **Enhancement of:** No content available.

## Description

Include system components that proactively seek to identify network-based malicious code or malicious websites.

## Discussion

External malicious code identification differs from decoys in \[SC-26\](\#sc-26) in that the components actively probe networks, including the Internet, in search of malicious code contained on external websites. Like decoys, the use of external malicious code identification techniques requires some supporting isolation measures to ensure that any malicious code discovered during the search and subsequently executed does not infect organizational systems. Virtualization is a common technique for achieving such isolation.

## Implementation guidance

No content available.

## CSF 2.0 subcategories

- [DE.CM-09](/md/csf/DE.CM-09.md) — DE.CM-09

## Related controls

- [SC-7](/md/controls/SC-7.md)
- [SC-26](/md/controls/SC-26.md)
- [SC-44](/md/controls/SC-44.md)
- [SI-3](/md/controls/SI-3.md)
- [SI-4](/md/controls/SI-4.md)

---

Derived from official NIST publications (NIST SP 800-53 Rev 5 and NIST CSF 2.0). nistcontrols.com is not affiliated with NIST.
