πΌ SC-7 BOUNDARY PROTECTION
- Contextual name: πΌ SC-7 BOUNDARY PROTECTION
- ID:
/frameworks/nist-sp-800-53-r4/sc/07
- Located in: πΌ SC SYSTEM AND COMMUNICATIONS PROTECTION
Descriptionβ
The information system: SC-7a. Monitors and controls communications at the external boundary of the system and at key internal boundaries within the system; SC-7b. Implements subnetworks for publicly accessible system components that are [Selection: physically; logically] separated from internal organizational networks; and SC-7c. Connects to external networks or information systems only through managed interfaces consisting of boundary protection devices arranged in accordance with an organizational security architecture.
Similarβ
- Internal
- ID:
dec-c-537a8fb7
- ID:
Similar Sections (Give Policies To)β
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ NIST CSF v1.1 β πΌ DE.CM-1: The network is monitored to detect potential cybersecurity events | 19 | 28 | ||
πΌ NIST CSF v1.1 β πΌ PR.AC-5: Network integrity is protected (e.g., network segregation, network segmentation) | 7 | 13 | ||
πΌ NIST CSF v1.1 β πΌ PR.DS-5: Protections against data leaks are implemented | 43 | 51 | ||
πΌ NIST CSF v1.1 β πΌ PR.PT-4: Communications and control networks are protected | 7 | 13 |
Sub Sectionsβ
Policies (6)β
Policy | Logic Count | Flags |
---|---|---|
π AWS EC2 Security Group allows public IPv4 (0.0.0.0/0) access to admin ports π’ | 1 | π’ x6 |
π AWS EC2 Security Group allows public IPv6 (::/0) access to admin ports π’ | 1 | π’ x6 |
π AWS EC2 Security Group allows unrestricted traffic to MongoDB π’ | 1 | π’ x6 |
π AWS EC2 Security Group allows unrestricted traffic to Oracle DBMS π’ | 1 | π’ x6 |
π AWS S3 Bucket is not configured to block public access π’ | 1 | π’ x6 |
π AWS S3 Bucket Policy is not set to deny HTTP requests π’ | 1 | π’ x6 |
Internal Rulesβ
Rule | Policies | Flags |
---|---|---|
βοΈ dec-x-63737248 | 1 | |
βοΈ dec-x-bcae85fb | 2 | |
βοΈ dec-x-d5fbfc40 | 1 | |
βοΈ dec-x-ec547a7c | 1 | |
βοΈ dec-z-c82c9f97 | 1 |