FedRAMP Controls / SC

SC-7(5) Deny by Default — Allow by Exception

Family SC
Baselines moderate
Mapped KSIs 2

Control statement

Deny network communications traffic by default and allow network communications traffic by exception {{ insert: param, sc-07.05_odp.01 }}.
        Guidance: For JAB Authorization, CSPs shall include details of this control in their Architecture Briefing

Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is preserved in the catalog database.

Covered by these Key Security Indicators

KSITitleCategory
KSI-CNA-01Restrict Network Traffic
_Persistently_ ensure all _machine-based_ _information resources_ are configured to limit inbound and outbound network traffic.
Cloud Native Architecture
KSI-CNA-02Attack Surface
_Persistently_ ensure _machine-based_ _information resources_ have a minimal attack surface and that lateral movement is minimized if compromised.
Cloud Native Architecture