manage.get.gov/docs/compliance/dist/system-security-plans/ato/sc-7.5.md
Logan McDonald 1d3dfdb8d5
Add compliance documentation to source control (#116)
* add initial setup of compliance-trestle
2022-09-14 08:46:43 -04:00

1.2 KiB

implementation-status control-origination
c-not-implemented
c-inherited-cloud-gov
c-inherited-cisa
c-common-control
c-system-specific-control

sc-7.5 - [catalog] Deny by Default — Allow by Exception

Control Statement

Deny network communications traffic by default and allow network communications traffic by exception No value found.

Control guidance

Denying by default and allowing by exception applies to inbound and outbound network communications traffic. A deny-all, permit-by-exception network communications traffic policy ensures that only those system connections that are essential and approved are allowed. Deny by default, allow by exception also applies to a system that is connected to an external system.

Control assessment-objective

network communications traffic is denied by default No value found; network communications traffic is allowed by exception No value found.


What is the solution and how is it implemented?

Add control implementation description here for control sc-7.5