FedRAMP Controls / SC
SC-7(5) Deny by Default — Allow by Exception
Family SC
Baselines moderate
Mapped KSIs 2
Control statement
Deny network communications traffic by default and allow network communications traffic by exception {{ insert: param, sc-07.05_odp.01 }}.
Guidance: For JAB Authorization, CSPs shall include details of this control in their Architecture Briefing Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is
preserved in the catalog database.
Covered by these Key Security Indicators
| KSI | Title | Category |
|---|---|---|
| KSI-CNA-01 | Restrict Network Traffic _Persistently_ ensure all _machine-based_ _information resources_ are configured to limit inbound and outbound network traffic. | Cloud Native Architecture |
| KSI-CNA-02 | Attack Surface _Persistently_ ensure _machine-based_ _information resources_ have a minimal attack surface and that lateral movement is minimized if compromised. | Cloud Native Architecture |