SV-259869r945595_rule
V-259869
SRG-NET-000391
SRG-NET-000391-CLD-000115
CAT II
10
This applies to all Impact Levels.
FedRAMP Moderate, High.
Configure the firewall and/or IDPS for continuous monitoring of all communications outbound from the virtual IaaS or PaaS.
Configure any ACLs and filtering rules on outbound interfaces to detect and filter unusual or unauthorized activities or conditions such as large file transfers, persistent connections, unusual protocols and ports in use, communication with unauthorized entities, or other unusually high traffic from particular segments or devices.
If this is a Software as a Service (SaaS), this is not applicable.
Inspect the firewall and/or or intrusion detection and prevention system (IDPS) access control lists (ACLs) and filtering rules that filter traffic on any outbound interface from the IaaS and systems.
Verify these rules are configured for continuous monitoring.
Verify the ACLs and security rules include rules and ACLs that detect and filter unusual or unauthorized activities or conditions such as large file transfers, persistent connections, unusual protocols and ports in use, communication with unauthorized entities, or other unusually high traffic from particular segments or devices.
If the IaaS/PaaS does not continuously monitor outbound communications to other enclaves and systems for unusual or unauthorized activities or conditions, this is a finding.
V-259869
False
SRG-NET-000391-CLD-000115
If this is a Software as a Service (SaaS), this is not applicable.
Inspect the firewall and/or or intrusion detection and prevention system (IDPS) access control lists (ACLs) and filtering rules that filter traffic on any outbound interface from the IaaS and systems.
Verify these rules are configured for continuous monitoring.
Verify the ACLs and security rules include rules and ACLs that detect and filter unusual or unauthorized activities or conditions such as large file transfers, persistent connections, unusual protocols and ports in use, communication with unauthorized entities, or other unusually high traffic from particular segments or devices.
If the IaaS/PaaS does not continuously monitor outbound communications to other enclaves and systems for unusual or unauthorized activities or conditions, this is a finding.
M
5583