Control Connections to Other Systems via a Deny-All and Allow-by-Exception Firewall PolicyID: oval:org.secpod.oval:def:80345 | Date: (C)2022-05-30 (M)2023-07-04 |
Class: COMPLIANCE | Family: macos |
A deny-all and allow-by-exception firewall policy _MUST_ be employed for managing connections to other systems. Organizations _MUST_ ensure the built-in packet filter firewall is configured correctly to employ the default deny rule. Failure to restrict network connectivity to authorized systems permits inbound connections from malicious systems. It also permits outbound connections that may facilitate the exfiltration of data. If you are using a third-party firewall solution, this setting does not apply.