Title
DENY BY DEFAULT / ALLOW BY EXCEPTION
Description
The information system at managed interfaces denies network communications traffic by default and allows network communications traffic by exception (i.e., deny all, permit by exception).
Supplemental
This control enhancement applies to both inbound and outbound network communications traffic. A deny-all, permit-by-exception network communications traffic policy ensures that only those connections which are essential and approved are allowed.
Reference Item Details
Category: SYSTEM AND COMMUNICATIONS PROTECTION
Parent Title: BOUNDARY PROTECTION
Family: SYSTEM AND COMMUNICATIONS PROTECTION
Baseline Impact: MODERATE,HIGH