NIST 800-171 Controls · System and Communications Protection

SC.2.013Control Mobile Code

CMMC Level 2SPRS if unmet: -1MEDIUM priority~4h to implement

Control and monitor the use of mobile code.

What SC.2.013 means in plain English

Mobile code means things like JavaScript, Java applets, ActiveX controls, and macros in Office documents — code that runs automatically when you visit a website or open a file. These can be used to attack your systems. Block Office macros from running by default (most ransomware starts with a macro), disable Java in browsers unless specifically needed, and use browser security settings to control what scripts can execute. An assessor wants to see you have thought about this and have protections in place.

The assessment question

Do you control mobile code execution by blocking Office macros by default, restricting browser plugins and scripts, and preventing unauthorized active content from running on systems containing CUI?

How to implement SC.2.013

  1. Block Office macros by default via Group Policy: User Configuration > Administrative Templates > Microsoft Office > Security Settings > "Block macros from running in Office files from the Internet" set to Enabled.
  2. Configure Windows Defender Attack Surface Reduction (ASR) rules to block Office applications from creating child processes and injecting code — this stops macro-based attacks.
  3. Remove or disable Java browser plugins on all workstations unless specifically required for a business application. Document any exceptions.
  4. Enable Windows SmartScreen: Settings > Privacy & Security > Windows Security > App & Browser Control > Reputation-based protection settings, enable all options.

Evidence your assessor will ask for

  • Group Policy configuration showing Office macros are blocked from internet sources
  • Windows Defender ASR rules configuration showing relevant protections enabled
  • Browser security settings showing script and plugin controls
  • Written policy on mobile code restrictions and any documented exceptions

Does AI prompt monitoring help with this control? Honestly, no.

SC.2.013 is met through the remediation steps above, not through AI traffic controls — an AI prompt firewall neither satisfies nor substitutes for it. We map AI monitoring only to the controls it genuinely evidences (flow control, boundary protection, audit, and incident support); for the full picture of where it does help, see the mapping guide linked below.

Full mapping: which 800-171 controls AI prompt monitoring evidences →

More System and Communications Protection controls

Score yourself against all 110 controls

The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.