Skip to main content

πŸ’Ό AC-4(21) Information Flow Enforcement | Physical or Logical Separation of Information Flows

  • Contextual name: πŸ’Ό AC-4(21) Information Flow Enforcement | Physical or Logical Separation of Information Flows
  • ID: /frameworks/nist-sp-800-53-r5/ac/04/21
  • Located in: πŸ’Ό AC-4 Information Flow Enforcement

Description​

Separate information flows logically or physically using [Assignment: organization-defined mechanisms and/or techniques] to accomplish [Assignment: organization-defined required separations by types of information].

Similar​

  • Sections
    • /frameworks/aws-fsbp-v1.0.0/api-gateway/04
    • /frameworks/aws-fsbp-v1.0.0/auto-scaling/05
    • /frameworks/aws-fsbp-v1.0.0/cloudfront/06
    • /frameworks/aws-fsbp-v1.0.0/dms/01
    • /frameworks/aws-fsbp-v1.0.0/documentdb/03
    • /frameworks/aws-fsbp-v1.0.0/ec2/01
    • /frameworks/aws-fsbp-v1.0.0/ec2/02
    • /frameworks/aws-fsbp-v1.0.0/ec2/09
    • /frameworks/aws-fsbp-v1.0.0/ec2/10
    • /frameworks/aws-fsbp-v1.0.0/ec2/15
    • /frameworks/aws-fsbp-v1.0.0/ec2/17
    • /frameworks/aws-fsbp-v1.0.0/ec2/18
    • /frameworks/aws-fsbp-v1.0.0/ec2/19
    • /frameworks/aws-fsbp-v1.0.0/ec2/21
    • /frameworks/aws-fsbp-v1.0.0/ec2/23
    • /frameworks/aws-fsbp-v1.0.0/ec2/25
    • /frameworks/aws-fsbp-v1.0.0/ec2/55
    • /frameworks/aws-fsbp-v1.0.0/ec2/56
    • /frameworks/aws-fsbp-v1.0.0/ec2/57
    • /frameworks/aws-fsbp-v1.0.0/ec2/58
    • /frameworks/aws-fsbp-v1.0.0/ec2/60
    • /frameworks/aws-fsbp-v1.0.0/ecs/02
    • /frameworks/aws-fsbp-v1.0.0/eks/01
    • /frameworks/aws-fsbp-v1.0.0/elasticache/07
    • /frameworks/aws-fsbp-v1.0.0/elb/12
    • /frameworks/aws-fsbp-v1.0.0/elb/14
    • /frameworks/aws-fsbp-v1.0.0/emr/01
    • /frameworks/aws-fsbp-v1.0.0/emr/02
    • /frameworks/aws-fsbp-v1.0.0/es/02
    • /frameworks/aws-fsbp-v1.0.0/lambda/01
    • /frameworks/aws-fsbp-v1.0.0/neptune/03
    • /frameworks/aws-fsbp-v1.0.0/network-firewall/06
    • /frameworks/aws-fsbp-v1.0.0/opensearch/02
    • /frameworks/aws-fsbp-v1.0.0/rds/01
    • /frameworks/aws-fsbp-v1.0.0/rds/02
    • /frameworks/aws-fsbp-v1.0.0/rds/23
    • /frameworks/aws-fsbp-v1.0.0/redshift/01
    • /frameworks/aws-fsbp-v1.0.0/redshift/07
    • /frameworks/aws-fsbp-v1.0.0/s3/01
    • /frameworks/aws-fsbp-v1.0.0/s3/02
    • /frameworks/aws-fsbp-v1.0.0/s3/03
    • /frameworks/aws-fsbp-v1.0.0/s3/19
    • /frameworks/aws-fsbp-v1.0.0/sagemaker/01
    • /frameworks/aws-fsbp-v1.0.0/sagemaker/02
    • /frameworks/aws-fsbp-v1.0.0/ssm/04
    • /frameworks/aws-fsbp-v1.0.0/waf/02
    • /frameworks/aws-fsbp-v1.0.0/waf/03
    • /frameworks/aws-fsbp-v1.0.0/waf/08
  • Internal
    • ID: dec-c-0c06ffcb

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [APIGateway.4] API Gateway should be associated with a WAF Web ACL11
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [Autoscaling.5] Amazon EC2 instances launched using Auto Scaling group launch configurations should not have Public IP addresses
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [CloudFront.6] CloudFront distributions should have WAF enabled
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [DMS.1] Database Migration Service replication instances should not be public
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [DocumentDB.3] Amazon DocumentDB manual cluster snapshots should not be public
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [EC2.1] Amazon EBS snapshots should not be publicly restorable
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [EC2.2] VPC default security groups should not allow inbound or outbound traffic1
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [EC2.9] Amazon EC2 instances should not have a public IPv4 address
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [EC2.10] Amazon EC2 should be configured to use VPC endpoints that are created for the Amazon EC2 service
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [EC2.15] Amazon EC2 subnets should not automatically assign public IP addresses
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [EC2.17] Amazon EC2 instances should not use multiple ENIs
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [EC2.18] Security groups should only allow unrestricted incoming traffic for authorized ports
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [EC2.19] Security groups should not allow unrestricted access to ports with high risk10
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [EC2.21] Network ACLs should not allow ingress from 0.0.0.0/0 to port 22 or port 33891
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [EC2.23] Amazon EC2 Transit Gateways should not automatically accept VPC attachment requests
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [EC2.25] Amazon EC2 launch templates should not assign public IPs to network interfaces
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [EC2.55] VPCs should be configured with an interface endpoint for ECR API
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [EC2.56] VPCs should be configured with an interface endpoint for Docker Registry
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [EC2.57] VPCs should be configured with an interface endpoint for Systems Manager
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [EC2.58] VPCs should be configured with an interface endpoint for Systems Manager Incident Manager Contacts
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [EC2.60] VPCs should be configured with an interface endpoint for Systems Manager Incident Manager
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [ECS.2] ECS services should not have public IP addresses assigned to them automatically
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [EKS.1] EKS cluster endpoints should not be publicly accessible
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [ElastiCache.7] ElastiCache clusters should not use the default subnet group
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [ELB.12] Application Load Balancer should be configured with defensive or strictest desync mitigation mode
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [ELB.14] Classic Load Balancer should be configured with defensive or strictest desync mitigation mode
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [EMR.1] Amazon EMR cluster primary nodes should not have public IP addresses
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [EMR.2] Amazon EMR block public access setting should be enabled
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [ES.2] Elasticsearch domains should not be publicly accessible
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [Lambda.1] Lambda function policies should prohibit public access
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [Neptune.3] Neptune DB cluster snapshots should not be public
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [NetworkFirewall.6] Stateless Network Firewall rule group should not be empty
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [Opensearch.2] OpenSearch domains should not be publicly accessible
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [RDS.1] RDS snapshot should be private11
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [RDS.2] RDS DB Instances should prohibit public access, as determined by the PubliclyAccessible configuration11
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [RDS.23] RDS instances should not use a database engine default port11
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [Redshift.1] Amazon Redshift clusters should prohibit public access
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [Redshift.7] Redshift clusters should use enhanced VPC routing
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [S3.1] S3 general purpose buckets should have block public access settings enabled1
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [S3.2] S3 general purpose buckets should block public read access
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [S3.3] S3 general purpose buckets should block public write access
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [S3.19] S3 access points should have block public access settings enabled
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [SageMaker.1] Amazon SageMaker AI notebook instances should not have direct internet access
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [SageMaker.2] SageMaker AI notebook instances should be launched in a custom VPC
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [SSM.4] SSM documents should not be public
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [WAF.2] AWS WAF Classic Regional rules should have at least one condition
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [WAF.3] AWS WAF Classic Regional rule groups should have at least one rule
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [WAF.8] AWS WAF Classic global web ACLs should have at least one rule or rule group

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό FedRAMP High Security Controls β†’ πŸ’Ό AC-4(21) Physical or Logical Separation of Information Flows (M)(H)1139

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags

Policies (39)​

PolicyLogic CountFlags
πŸ“ AWS API Gateway REST API Stage is not associated with a WAF Web ACL 🟒1🟒 x6
πŸ“ AWS EC2 Default Security Group does not restrict all traffic 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows public IPv4 (0.0.0.0/0) access to admin ports 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows public IPv6 (::/0) access to admin ports 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows unrestricted CIFS traffic 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows unrestricted DNS traffic 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows unrestricted FTP traffic 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows unrestricted ICMP traffic 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows unrestricted NetBIOS traffic 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows unrestricted RPC traffic 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows unrestricted SMTP traffic 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows unrestricted traffic to MongoDB 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows unrestricted traffic to MSSQL 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows unrestricted traffic to MySQL 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows unrestricted traffic to Oracle DBMS 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows unrestricted traffic to PostgreSQL 🟒1🟒 x6
πŸ“ AWS EC2 Security Group allows unrestricted Telnet traffic 🟒1🟒 x6
πŸ“ AWS IAM Policy allows full administrative privileges 🟒1🟒 x6
πŸ“ AWS RDS Instance is publicly accessible and in an unrestricted public subnet 🟒1🟒 x6
πŸ“ AWS RDS Instance uses default endpoint port 🟒1🟒 x6
πŸ“ AWS RDS Snapshot is publicly accessible 🟒1🟒 x6
πŸ“ AWS S3 Bucket is not configured to block public access 🟒1🟒 x6
πŸ“ AWS VPC Network ACL exposes admin ports to public internet ports 🟒1🟒 x6
πŸ“ Azure Cosmos DB Account Private Endpoints are not used 🟒1🟒 x6
πŸ“ Azure Cosmos DB Account Virtual Network Filter is not enabled 🟒1🟒 x6
πŸ“ Azure Cosmos DB Entra ID Client Authentication is not used 🟒🟒 x3
πŸ“ Azure Key Vault Private Endpoints are not used 🟒1🟒 x6
πŸ“ Azure Managed Disk Public Network Access is not disabled 🟒1🟒 x6
πŸ“ Azure Network Security Group allows unrestricted HTTP(S) access from the Internet 🟒1🟒 x6
πŸ“ Azure Network Security Group allows unrestricted RDP access from the Internet 🟒1🟒 x6
πŸ“ Azure Network Security Group allows unrestricted SSH access from the Internet 🟒1🟒 x6
πŸ“ Azure Network Security Group allows unrestricted UDP access from the Internet 🟒1🟒 x6
πŸ“ Azure PostgreSQL Flexible Server Firewall Rules allow access to Azure services 🟒1🟒 x6
πŸ“ Azure SQL Database allows ingress from 0.0.0.0/0 (ANY IP) 🟒1🟒 x6
πŸ“ Azure SQL Server Public Network Access is not disabled 🟒1🟒 x6
πŸ“ Azure Storage Account Allow Blob Anonymous Access is set enabled 🟒1🟒 x6
πŸ“ Azure Storage Account Cross Tenant Replication is enabled 🟒1🟒 x6
πŸ“ Azure Storage Account Default Network Access Rule is not set to Deny 🟒1🟒 x6
πŸ“ Azure Storage Account Private Endpoints are not used 🟒1🟒 x6

Internal Rules​

RulePoliciesFlags
βœ‰οΈ dec-x-3e379c671
βœ‰οΈ dec-x-4c15a09f1
βœ‰οΈ dec-x-4f30f24e1
βœ‰οΈ dec-x-6eab9b881
βœ‰οΈ dec-x-11c3009f1
βœ‰οΈ dec-x-14bf01f31
βœ‰οΈ dec-x-42a090841
βœ‰οΈ dec-x-46a83a301
βœ‰οΈ dec-x-157aa4b91
βœ‰οΈ dec-x-0289e9c91
βœ‰οΈ dec-x-293ab45b1
βœ‰οΈ dec-x-397dd59e1
βœ‰οΈ dec-x-599c86b41
βœ‰οΈ dec-x-807a37c91
βœ‰οΈ dec-x-66358b451
βœ‰οΈ dec-x-083928f51
βœ‰οΈ dec-x-637372481
βœ‰οΈ dec-x-a7d8f0e71
βœ‰οΈ dec-x-b4d3d9dc2
βœ‰οΈ dec-x-b17c005c1
βœ‰οΈ dec-x-b33429051
βœ‰οΈ dec-x-bcae85fb2
βœ‰οΈ dec-x-bf1f13f61
βœ‰οΈ dec-x-bfdadcc41
βœ‰οΈ dec-x-ca1c0c0d1
βœ‰οΈ dec-x-d127f4071
βœ‰οΈ dec-x-e43fd12e1
βœ‰οΈ dec-x-ec547a7c1
βœ‰οΈ dec-x-ecd99f881
βœ‰οΈ dec-x-f4cc003a1
βœ‰οΈ dec-x-f12d78aa1
βœ‰οΈ dec-x-f937c35f1
βœ‰οΈ dec-z-c82c9f971
βœ‰οΈ dec-z-dbeeed9f1
βœ‰οΈ dec-z-f778950c1