SC-7 (5) - Deny by Default / Allow by Exception [FSv1.1]
This control is based on IBM Cloud Framework for Financial Services v1.1.
Control requirements
- SC-7 (5) - 0
- The information system at managed interfaces denies network communications traffic by default and allows network communications traffic by exception (i.e., deny all, permit by exception).
Implementation guidance
See the resources that follow to learn more about how to implement this control.
- Accessing the public internet
- Connecting application provider to the management VPC
- Connectivity to IBM Cloud services with private endpoints
- Consumer connectivity to workload VPC
- Creating and connecting the management and workload VPCs
- IBM Cloud account setup
- Working with Red Hat OpenShift on IBM Cloud
NIST supplemental guidance
This control enhancement applies to both inbound and outbound network communications traffic. A deny-all, permit-by-exception network communications traffic policy ensures that only those connections which are essential and approved are allowed.