id: "SC-07(05)" title: "Deny by Default — Allow by Exception" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-07.05" priority: "P1" implementation_level: "system" parent: "SC-07" enhancement: True


Statement

Deny network communications traffic by default and allow network communications traffic by exception {{ insert: param, sc-07.05_odp.01 }}.

Guidance

Denying by default and allowing by exception applies to inbound and outbound network communications traffic. A deny-all, permit-by-exception network communications traffic policy ensures that only those system connections that are essential and approved are allowed. Deny by default, allow by exception also applies to a system that is connected to an external system.

Assessment Objective: network communications traffic is denied by default {{ insert: param, sc-07.05_odp.01 }};

Assessment Objective: network communications traffic is allowed by exception {{ insert: param, sc-07.05_odp.01 }}.

System and communications protection policy

procedures addressing boundary protection

system design documentation

system configuration settings and associated documentation

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

system developer

organizational personnel with boundary protection responsibilities

Mechanisms implementing traffic management at managed interfaces