id: "SC-07(18)" title: "Fail Secure" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-07.18" priority: "P1" implementation_level: "system" parent: "SC-07" enhancement: True


Statement

Prevent systems from entering unsecure states in the event of an operational failure of a boundary protection device.

Guidance

Fail secure is a condition achieved by employing mechanisms to ensure that in the event of operational failures of boundary protection devices at managed interfaces, systems do not enter into unsecure states where intended security properties no longer hold. Managed interfaces include routers, firewalls, and application gateways that reside on protected subnetworks (commonly referred to as demilitarized zones). Failures of boundary protection devices cannot lead to or cause information external to the devices to enter the devices nor can failures permit unauthorized information releases.

Assessment Objective

systems are prevented from entering unsecure states in the event of an operational failure of a boundary protection device.

System and communications protection policy

procedures addressing boundary protection

system design documentation

system architecture

system configuration settings and associated documentation

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

system developer

organizational personnel with boundary protection responsibilities

Mechanisms supporting and/or implementing secure failure