# SC-37 — Out-of-band Channels

- **Control ID:** SC-37
- **Family:** [SC](/md/families/SC.md)
- **Baselines:** No content available.
- **Enhancement of:** No content available.

## Description

Employ the following out-of-band channels for the physical delivery or electronic transmission of \[assignment\] to \[assignment\]: \[assignment\].

## Discussion

Out-of-band channels include local, non-network accesses to systems; network paths physically separate from network paths used for operational traffic; or non-electronic paths, such as the U.S. Postal Service. The use of out-of-band channels is contrasted with the use of in-band channels (i.e., the same channels) that carry routine operational traffic. Out-of-band channels do not have the same vulnerability or exposure as in-band channels. Therefore, the confidentiality, integrity, or availability compromises of in-band channels will not compromise or adversely affect the out-of-band channels. Organizations may employ out-of-band channels in the delivery or transmission of organizational items, including authenticators and credentials; cryptographic key management information; system and data backups; configuration management changes for hardware, firmware, or software; security updates; maintenance information; and malicious code protection updates. For example, cryptographic keys for encrypted files are delivered using a different channel than the file.

## Implementation guidance

No content available.

## CSF 2.0 subcategories

No content available.

## Related controls

- [AC-2](/md/controls/AC-2.md)
- [CM-3](/md/controls/CM-3.md)
- [CM-5](/md/controls/CM-5.md)
- [CM-7](/md/controls/CM-7.md)
- [IA-2](/md/controls/IA-2.md)
- [IA-4](/md/controls/IA-4.md)
- [IA-5](/md/controls/IA-5.md)
- [MA-4](/md/controls/MA-4.md)
- [SC-12](/md/controls/SC-12.md)
- [SI-3](/md/controls/SI-3.md)
- [SI-4](/md/controls/SI-4.md)
- [SI-7](/md/controls/SI-7.md)

---

Derived from official NIST publications (NIST SP 800-53 Rev 5 and NIST CSF 2.0). nistcontrols.com is not affiliated with NIST.
