SC-6 System and Communications Protection

Resource Availability

High Risk Moderate Medium Cost

SC-6 protects information system availability by allocating organization-defined resources according to priority and/or by safeguarding against resource exhaustion. Clinical systems need CPU, memory, storage, and network protections so ransomware encryption storms, runaway interfaces, or DoS conditions do not take down EHR and ancillary care systems.

Control Objective

Allocate and safeguard computing resources so defined ePHI services remain available under contention, misuse, or attack.

Implementation Guidance

  1. Identify critical ePHI services and set resource priorities (QoS, cluster reservations).
  2. Apply rate limits and connection limits on edge and API gateways.
  3. Quotas on noisy tenants/interfaces sharing platforms.
  4. Monitor saturation (CPU, disk, file descriptors) with capacity alerts.
  5. Separate noisy analytics from OLTP EHR databases.
  6. Include storage headroom for audit and clinical growth.
  7. Test failover capacity, not only functional failover.
  8. Align with SC-5 DoS protections and CP capacity planning.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Interface storm saturates engine

Misconfigured ADT loop floods the engine; SC-6 rate limits and process priorities keep EHR login services responsive.

Ransomware encryption spike

EDR and storage anomaly controls detect resource exhaustion patterns early; critical VMs have reserved IOPS.

Shared VDI oversubscription

Clinic open Monday exhausts VDI pool; capacity management under SC-6 expands pools before charting fails.

Best Practices

  • Priority/reservation for critical clinical services.
  • Rate limits at edges.
  • Separate noisy workloads.
  • Capacity monitoring and alerts.
  • Test under load.
  • Pair with SC-5 and CP-2.

Common Gaps & Violations

  • Best-effort everything on one cluster.
  • No rate limits on public patient portals.
  • Analytics jobs starving OLTP.
  • Ignoring disk-full as availability risk.
  • Failover nodes undersized.

Required Documentation

  • Resource availability standard (SC-6)
  • Critical service priority list
  • Rate limit / quota configs
  • Capacity monitoring evidence
  • Load/failover test results

How to Test & Validate

  1. Review resource reservations for EHR tier.
  2. Load-test or review recent peak metrics vs limits.
  3. Confirm rate limits on portal/API.
  4. Verify alerts for saturation.
  5. Check analytics isolation from OLTP.

Audit Considerations

SC-6 is availability engineering evidence—quotas, priorities, and safeguards—not only uptime SLAs on slides.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(7) Contingency Plan — availability of ePHI systems.
  • 164.312(a) Access Control — users cannot access unavailable systems.
  • 164.308(a)(1) Risk Analysis — DoS and exhaustion are availability threats.
  • 164.310(a) Facility — physical capacity pairs with logical resource controls.

Compliance Tips

  • Put EHR and IdP on reserved capacity classes.
  • Treat disk-full on audit/DB volumes as Sev-1.
  • Review noisy neighbor risks after every major onboarding.

Frequently Asked Questions

Is SC-6 the same as SC-5?

SC-5 focuses on DoS protection; SC-6 focuses on resource allocation/safeguards for availability more broadly.

Does cloud autoscaling meet SC-6?

It can, if configured with limits, budgets, and protections against runaway scale abuse—and documented.

Are medical devices in scope?

Organization-defined; shared clinical networks should not let one device exhaust resources affecting others.

References & Resources

  • NIST SP 800-53 Rev. 5 — SC-6
  • Related controls: SC-5, CP-2, SI-13, AU-4

Need Help Implementing SC-6?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.