3.13 System & Communications Protection5 pts

3.13.6 — Deny all, permit by exception

Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).

Your firewall should block everything by default and only allow the traffic you've explicitly approved.

What it actually means

Network traffic should be denied by default; you open only the specific ports, protocols, and destinations the business needs. This is the opposite of 'allow everything except known-bad.' It applies at your perimeter firewall and, ideally, between internal segments too.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.

Calculate your SPRS score →Draft your SSP language →

Connected requirements

More in System & Communications Protection (3.13)

← Back to the Control Library

The GovCon Compliance Brief
Get the next regulation change explained in plain English.

One CMMC / NIST 800-171 update, decoded, every other week. No spin, no sales pitch. Free.