CCI-001105
CCI-001105 Definition
Document each exception to the traffic flow policy with a supporting mission or business need and duration of that need.
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed documents each exception to the traffic flow policy with a supporting mission/business need and duration of that need for each external telecommunication service.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the documented exceptions to the traffic flow policy to ensure the organization being inspected/assessed identifies each exception with supporting mission/business need and duration of that need for each external telecommunication service.
Compelling Evidence
1.) Signed and dated traffic flow policy document. 2.) Network diagram. 3.) Applicable firewall rule set. 4.) Applicable firewall logs.