HOME

SC-7 (4)

SC-7 (4) H M
Description

The organization:
(a) Implements a managed interface for each external telecommunication service;
(b) Establishes a traffic flow policy for each managed interface;
(c) Protects the confidentiality and integrity of the information being transmitted across each interface;
(d) Documents each exception to the traffic flow policy with a supporting mission/business need and duration of that need; and
(e) Reviews exceptions to the traffic flow policy [Assignment: organization-defined frequency] and removes exceptions that are no longer supported by an explicit mission/business need.

FedRAMP
  • H SC-7 (4) (e) [at least every ninety (90) days or whenever there is a change in the threat environment that warrants a review of the exceptions]
  • M SC-7 (4) (e) [at least annually]
DISA Cloud Computing SRG

e. every 180 days

Source:
DoD RMF TAG

Supplemental Guidance

Related Controls