Your firewall should block everything by default and only allow the traffic you've explicitly approved.
What it actually means
Network traffic should be denied by default; you open only the specific ports, protocols, and destinations the business needs. This is the opposite of 'allow everything except known-bad.' It applies at your perimeter firewall and, ideally, between internal segments too.
Pass or fail — an assessor needs a "yes" to each
- Does your firewall default-deny inbound (and ideally outbound), allowing only explicitly approved traffic?
- Is there a documented list of approved ports / services with a business justification?
What to have ready
- Firewall ruleset showing a default-deny posture
- Documented allow-list of ports / protocols / services with justifications
Where teams trip up
- Default-allow outbound with only a few blocks
- Accumulated 'any-any' rules no one has reviewed
See where this control puts your score
Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.
Calculate your SPRS score →Draft your SSP language →Connected requirements
3.4.7 — Blocking nonessential ports and services3.13.1 — Boundary protection3.13.5 — Separating public segments
More in System & Communications Protection (3.13)
3.13.1 — Protect your boundaries3.13.2 — Build security in by design3.13.3 — Separate user and admin functions3.13.4 — Stop data leaking through shared resources3.13.5 — Wall off your public-facing systems3.13.7 — Block split tunneling on VPNs3.13.8 — Encrypt CUI in transit3.13.9 — Drop idle network sessions3.13.10 — Manage your encryption keys3.13.11 — FIPS-validated cryptography3.13.12 — Control cameras and microphones3.13.13 — Control mobile code3.13.14 — Control and monitor VoIP3.13.15 — Protect session authenticity3.13.16 — Encrypt CUI at rest