SC-7(4): External Telecommunications Services

CSF v1.1 References:

Baselines:

  • Moderate
  • High

Next Version:

Control Statement

The organization:

  1. Implements a managed interface for each external telecommunication service;
  2. Establishes a traffic flow policy for each managed interface;
  3. Protects the confidentiality and integrity of the information being transmitted across each interface;
  4. Documents each exception to the traffic flow policy with a supporting mission/business need and duration of that need; and
  5. Reviews exceptions to the traffic flow policy [Assignment: organization-defined frequency] and removes exceptions that are no longer supported by an explicit mission/business need.