HomeControl Library › 3.13.6
3.13 System & Communications Protection5 pts

3.13.6 — Deny all, permit by exception

Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).

Your firewall should block everything by default and only allow the traffic you've explicitly approved.

What it actually means

Network traffic should be denied by default; you open only the specific ports, protocols, and destinations the business needs. This is the opposite of 'allow everything except known-bad.' It applies at your perimeter firewall and, ideally, between internal segments too.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library