NIST 800-171 Controls · System and Communications Protection
SC.2.013 — Control Mobile Code
Control and monitor the use of mobile code.
What SC.2.013 means in plain English
Mobile code means things like JavaScript, Java applets, ActiveX controls, and macros in Office documents — code that runs automatically when you visit a website or open a file. These can be used to attack your systems. Block Office macros from running by default (most ransomware starts with a macro), disable Java in browsers unless specifically needed, and use browser security settings to control what scripts can execute. An assessor wants to see you have thought about this and have protections in place.
The assessment question
“Do you control mobile code execution by blocking Office macros by default, restricting browser plugins and scripts, and preventing unauthorized active content from running on systems containing CUI?”
How to implement SC.2.013
- Block Office macros by default via Group Policy: User Configuration > Administrative Templates > Microsoft Office > Security Settings > "Block macros from running in Office files from the Internet" set to Enabled.
- Configure Windows Defender Attack Surface Reduction (ASR) rules to block Office applications from creating child processes and injecting code — this stops macro-based attacks.
- Remove or disable Java browser plugins on all workstations unless specifically required for a business application. Document any exceptions.
- Enable Windows SmartScreen: Settings > Privacy & Security > Windows Security > App & Browser Control > Reputation-based protection settings, enable all options.
Evidence your assessor will ask for
- Group Policy configuration showing Office macros are blocked from internet sources
- Windows Defender ASR rules configuration showing relevant protections enabled
- Browser security settings showing script and plugin controls
- Written policy on mobile code restrictions and any documented exceptions
Does AI prompt monitoring help with this control? Honestly, no.
SC.2.013 is met through the remediation steps above, not through AI traffic controls — an AI prompt firewall neither satisfies nor substitutes for it. We map AI monitoring only to the controls it genuinely evidences (flow control, boundary protection, audit, and incident support); for the full picture of where it does help, see the mapping guide linked below.
Full mapping: which 800-171 controls AI prompt monitoring evidences →
More System and Communications Protection controls
Monitor and Protect Communications at Boundaries
SC.1.005Implement Subnetworks for Public Components
SC.2.002Employ Effective Security Architecture
SC.2.003Separate User and System Management Functionality
SC.2.004Prevent Unauthorized Info Transfer via Shared Resources
SC.2.006Deny Network Traffic by Default
Score yourself against all 110 controls
The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.