Skip to content
Pass My CMMC
Practices Start Here Prep Timeline Glossary About

System-Communications

SC.L2-3.13.3
SC.L2-3.13.3: Security Function Isolation
Separate user functionality from system management.
medium
SC.L2-3.13.4
SC.L2-3.13.4: Shared Resource Control
Prevent unauthorized or unintended information transfer via shared resources.
medium
SC.L2-3.13.5
SC.L2-3.13.5: Public-Access System Separation
Deny network communications traffic by default on external interfaces.
hard
SC.L2-3.13.6
SC.L2-3.13.6: Network Communication by Exception
Deny network communications by default, allow by exception.
hard
SC.L2-3.13.7
SC.L2-3.13.7: Split Tunneling
Prevent remote devices from simultaneously establishing non-remote connections.
medium
SC.L2-3.13.9
SC.L2-3.13.9: Network Disconnect
Terminate network connections at end of session or after inactivity.
easy
SC.L2-3.13.10
SC.L2-3.13.10: Key Management
Establish and manage cryptographic keys.
medium
SC.L2-3.13.11
SC.L2-3.13.11: CUI Encryption
Employ FIPS-validated cryptography for CUI.
hard
SC.L2-3.13.12
SC.L2-3.13.12: Collaborative Computing
Prohibit remote activation of collaborative computing devices.
easy
SC.L2-3.13.13
SC.L2-3.13.13: Mobile Code
Control and monitor the use of mobile code.
medium
SC.L2-3.13.14
SC.L2-3.13.14: Voice over Internet Protocol
Control and monitor the use of VoIP.
easy
SC.L2-3.13.15
SC.L2-3.13.15: Communications Authenticity
Protect the authenticity of communications sessions.
medium
SC.L2-3.13.16
SC.L2-3.13.16: Data at Rest
Protect CUI at rest.
medium

Pass My CMMC

Site

All Practices Start Here CMMC Levels Explained Assessment Day Glossary About

Popular Families

Access Control (AC) Incident Response (IR) System Protection (SC) All 14 families

Newsletter

Subscribe on Substack

© 2026 Pass My CMMC. This site provides general guidance based on real assessment experience. It is not legal, compliance, or professional advice. Your organization's situation is unique. Work with qualified professionals for formal assessment preparation.