Overview

Security Requirements for 03.13.06 Network Communication by Exception

This requirement applies to inbound and outbound network communications traffic at the system boundary and at identified points within the system. A deny-all, permit-by-exception network communications traffic policy ensures that only those connections which are essential and approved are allowed.

Evidence

  1. 03.13.06.a

    Network communications traffic is denied by default

  1. 03.13.06.b

    Network communications traffic is allowed by exception