SC-34 System and Communications Protection

Non-Modifiable Executable Programs

Medium Risk Complex Medium Cost

SC-34 loads and executes organization-defined applications from hardware-enforced, write-protected storage or other non-modifiable forms. Clinical kiosks, appliance firewalls, and hardened jump hosts benefit when the executable set cannot be casually rewritten by malware.

Control Objective

Ensure defined executables for high-risk ePHI-supporting components execute from non-modifiable or hardware-protected storage as specified.

Implementation Guidance

  1. Select components suited to immutability (kiosks, appliances, secure admin bastions).
  2. Use measured boot, signed images, or write-protect mechanisms.
  3. Rebuild/redeploy rather than patch in place when using immutable patterns.
  4. Control who can unlock and update images via CAB/PAM.
  5. Monitor integrity violations (SI-7).
  6. Document medical device limitations where OEMs cannot support SC-34.
  7. Pair with CM-7 deny-by-default.
  8. Test update procedures so immutability does not block urgent clinical patches.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Patient check-in kiosk

Kiosk OS boots a signed image; users cannot install software; malware writes do not persist across reboot.

PAM jump host

Admin bastion uses immutable base image refreshed from trusted pipeline after each patch cycle.

Network appliance

Boundary firewall executes from vendor signed, non-user-writable partitions.

Best Practices

  • Apply where operationally realistic.
  • Signed/immutable images.
  • Controlled update pipeline.
  • Integrity monitoring.
  • OEM exception tracking.
  • Do not block emergency patch paths.

Common Gaps & Violations

  • Writable system volumes on kiosks.
  • Claiming SC-34 enterprise-wide without mechanisms.
  • No process to update immutable hosts.
  • Ignoring integrity alerts.
  • Unmanaged biomedical PCs as “kiosks.”

Required Documentation

  • Non-modifiable executable standard (SC-34)
  • In-scope component list
  • Image/write-protect configuration
  • Update/rebuild runbooks
  • Exception register

How to Test & Validate

  1. Attempt persistence on a kiosk—expect wipe on reboot or block.
  2. Verify update pipeline requires approval.
  3. Confirm integrity alerts.
  4. Review appliance write-protect settings.
  5. Validate exception list currency.

Audit Considerations

SC-34 is selective hardening. Show specific components and mechanisms rather than a blanket statement.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(c) Integrity — protect against improper alteration of systems hosting ePHI.
  • 164.310(c) Workstation Security — kiosks/workstations that access ePHI.
  • 164.308(a)(1) Risk Analysis — malware persistence is a key threat.
  • 164.312(b) Audit Controls — monitor integrity events.

Compliance Tips

  • Start with patient-facing kiosks and admin bastions.
  • Align SC-34 with allowlisting and EDR.
  • Keep a fast rebuild path for urgent CVEs.

Frequently Asked Questions

Must the entire EHR be read-only?

No—apply to organization-defined components where non-modifiable execution is practical.

Is AppLocker enough?

It helps but is not always hardware-enforced write protection; combine controls as needed.

Related to CM-14?

CM-14 verifies signatures; SC-34 emphasizes execution from non-modifiable storage.

References & Resources

  • NIST SP 800-53 Rev. 5 — SC-34
  • Related controls: CM-5, CM-7, SI-7, SC-3

Need Help Implementing SC-34?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.