---
name: framework-financial-services-controls-sc-5
title: SC-5 - Denial-of-service Protection
description: '_[IBM Assignment: Protect against]_ the effects of the following types of denial-of-service events: _[IBM Assignment: application and volumetric based attacks (OSI layers 3, 4, 6, and 7)]_.'
last-updated: 2026-08-26
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/framework-financial-services-controls?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# SC-5 - Denial-of-service Protection
{: #sc-5}

## Control requirements
{: #control-requirements}



### SC-5 (a)
{: #sc-5-a}


_[IBM Assignment: Protect against]_ the effects of the following types of denial-of-service events: _[IBM Assignment: application and volumetric based attacks (OSI layers 3, 4, 6, and 7)]_.


### SC-5 (b)
{: #sc-5-b}


Employ the following controls to achieve the denial-of-service objective: _[IBM Assignment: annual testing of the documented DoS and DDoS mitigation technologies]_.









## Implementation guidance
{: #implementation-guidance}

See the resources that follow to learn more about how to implement this control.


- [Connectivity to IBM Cloud services with Satellite Link](https://cloud.ibm.com/docs/framework-financial-services?topic=framework-financial-services-satellite-architecture-connectivity-to-services&format=markdown)


- [Ensuring isolation between Satellite management functions and workload functions](https://cloud.ibm.com/docs/framework-financial-services?topic=framework-financial-services-satellite-architecture-connectivity-management-isolation&format=markdown)


- [Accessing external resources from the Satellite location](https://cloud.ibm.com/docs/framework-financial-services?topic=framework-financial-services-satellite-architecture-connectivity-to-external&format=markdown)


- [Consumer connectivity to workload resources](https://cloud.ibm.com/docs/framework-financial-services?topic=framework-financial-services-satellite-architecture-connectivity-workload&format=markdown)


- [Creating and connecting the management and workload VPCs](https://cloud.ibm.com/docs/framework-financial-services?topic=framework-financial-services-vpc-architecture-connectivity-create-vpcs&format=markdown)


- [Accessing the public internet](https://cloud.ibm.com/docs/framework-financial-services?topic=framework-financial-services-vpc-architecture-connectivity-to-internet&format=markdown)


- [Connectivity to IBM Cloud services with private endpoints](https://cloud.ibm.com/docs/framework-financial-services?topic=framework-financial-services-vpc-architecture-connectivity-to-services&format=markdown)


- [Consumer connectivity to workload VPC](https://cloud.ibm.com/docs/framework-financial-services?topic=framework-financial-services-vpc-architecture-connectivity-workload&format=markdown)






## NIST supplemental guidance
{: #nist-supplemental-guidance}

Denial-of-service events may occur due to a variety of internal and external causes, such as an attack by an adversary or a lack of planning to support organizational needs with respect to capacity and bandwidth. Such attacks can occur across a wide range of network protocols (e.g., IPv4, IPv6). A variety of technologies are available to limit or eliminate the origination and effects of denial-of-service events. For example, boundary protection devices can filter certain types of packets to protect system components on internal networks from being directly affected by or the source of denial-of-service attacks. Employing increased network capacity and bandwidth combined with service redundancy also reduces the susceptibility to denial-of-service events.