Overview

Security Requirements for 03.13.05 Public-Access System Separation

Subnetworks that are physically or logically separated from internal networks are referred to as demilitarized zones (DMZs). DMZs are typically implemented with boundary control devices and techniques that include routers, gateways, firewalls, virtualization, or cloud-based technologies. [SP 800-41] provides guidance on firewalls and firewall policy. [SP 800-125B] provides guidance on security for virtualization technologies.

Evidence

  1. 03.13.05.a

    Publicly accessible system components are identified

  1. 03.13.05.b

    Subnetworks for publicly accessible system components are physically or logically separated from internal networks