TDA-02.5 ยท Identification & Justification of Ports, Protocols & Services

Control Description

Mechanisms exist to require process owners to identify, document and justify the business need for the ports, protocols and other services necessary to operate their technology solutions.

Control Question
Assessment question for control validation

Does the organization require process owners to identify, document and justify the business need for the ports, protocols and other services necessary to operate their technology solutions?

Control Weighting
8
Validation Cadence
Annual
NIST CSF Function
Identify
Supply Chain Risk Management (SCRM) Tiers
Applicable SCRM tier levels for this control
Tier 2 - Operational
Tier 3 - Tactical
Additional Metadata
Applicability (Process):
x