Mapped to NIST 800-171 Requirement: 3.13.1
CMMC Assessment Objective: SC.L2-3.13.1[a]
What This Control Means
You must clearly identify how your organization protects the network and system boundaries where CUI enters, exits, or is transmitted.
This includes protections between:
• Internal systems and the public internet
• Enclave environments and corporate networks
• Cloud services and on-premises infrastructure
• Managed service providers and your CUI systems
Why It Matters
Boundary protections prevent:
• Unauthorized access
• Malware infiltration
• Exfiltration of CUI
• Traffic from bypassing security inspection
This control establishes the first line of defense around your sensitive systems.
How to Implement It
1. Define Your Network Boundaries
• Identify:
◦ Internet gateways
◦ Cloud interconnects
◦ Remote access portals
◦ VPN connections
◦ Firewalls and DMZs
2. Identify the Protection Methods You Use Examples include:
• Firewalls
• Intrusion prevention/detection systems (IPS/IDS)
• Application proxies or content filters
• Segmentation (e.g., VLANs or SD-WANs)
• Encryption for data-in-transit across boundaries
3. Map Protections to CUI Flows
• Document which protections exist at points where CUI enters or leaves systems
• Highlight what filters or inspections are used
4. Describe the Capabilities
• What each control does (e.g., packet filtering, traffic analysis)
• What traffic is inspected or blocked
Evidence the Assessor Will Look For
• Diagrams showing network and system boundaries
• Descriptions of boundary protection methods in your SSP
• Lists of boundary protection devices or configurations
• Roles and responsibilities for managing boundary controls
• Risk assessments identifying where boundaries exist and how they’re protected
Common Gaps
• Boundaries not clearly defined or documented
• No formal identification of what protects each boundary
• Protections in place but untested or inconsistently deployed
• Missing visibility into third-party or cloud boundaries
How Cuick Trac Helps
Cuick Trac supports this requirement by:
• Mapping system boundaries tied to CUI flows
• Documenting protection mechanisms in your SSP
• Linking controls to network diagrams and technical assets
• Supporting system boundary reviews during audits or change control
• Helping define roles and risk considerations related to perimeter security
With Cuick Trac, your system boundaries are visible, understood, and protected by design.
Final CTA
Your first line of defense is your boundary—know how you protect it.
Schedule a Cuick Trac demo to identify and document your boundary protection methods with confidence and compliance.