id: "SC-07(18)" title: "Fail Secure" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-07.18" priority: "P1" implementation_level: "system" parent: "SC-07" enhancement: True
Statement
Prevent systems from entering unsecure states in the event of an operational failure of a boundary protection device.
Guidance
Fail secure is a condition achieved by employing mechanisms to ensure that in the event of operational failures of boundary protection devices at managed interfaces, systems do not enter into unsecure states where intended security properties no longer hold. Managed interfaces include routers, firewalls, and application gateways that reside on protected subnetworks (commonly referred to as demilitarized zones). Failures of boundary protection devices cannot lead to or cause information external to the devices to enter the devices nor can failures permit unauthorized information releases.
Assessment Objective
systems are prevented from entering unsecure states in the event of an operational failure of a boundary protection device.
System and communications protection policy
procedures addressing boundary protection
system design documentation
system architecture
system configuration settings and associated documentation
system audit records
system security plan
other relevant documents or records
System/network administrators
organizational personnel with information security responsibilities
system developer
organizational personnel with boundary protection responsibilities
Mechanisms supporting and/or implementing secure failure