NET-04.10 ยท Detection of Unsanctioned Information

Control Description

Automated mechanisms exist to implement security policy filters requiring fully enumerated formats that restrict data structure and content, when transferring information between different security domains.

Control Question
Assessment question for control validation

Does the organization use automated mechanisms to implement security policy filters requiring fully enumerated formats that restrict data structure and content, when transferring information between different security domains?

Control Weighting
5
Validation Cadence
Quarterly
NIST CSF Function
Detect
Supply Chain Risk Management (SCRM) Tiers
Applicable SCRM tier levels for this control
Tier 2 - Operational
Tier 3 - Tactical