PlumbTrackLive demoGRC Risk System

← internal audit

Audit — SC-7 — Boundary Protection

Framework: NIST SP 800-53 Rev.5 SC-7 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 7 checked
Examine Review current network architecture/topology diagrams to confirm every connection to an external network traverses a managed interface (firewall/gateway/proxy) and that publicly accessible components reside in a separate DMZ subnetwork logically isolated from internal networks (CIS Control 12).
Examine Inspect the rulesets on boundary devices to confirm a deny-all/default-deny posture where traffic is permitted only by documented, business-justified exceptions (allow-by-exception), and that each rule maps to an approved request (CIS Controls 4 and 13).
Test From an external/untrusted network, attempt connections (e.g., port scan or session initiation) to internal-only services and confirm the boundary blocks them, and that management/split-tunnel traffic is not permitted to bypass the managed interface.
Interview Ask network/security personnel how the inventory of external system connections and interfaces is maintained and how unauthorized or rogue connections (shadow ISPs, unmanaged tunnels) are detected and removed.
Examine Examine firewall rule review/recertification records to confirm rulesets are reviewed at the organization-defined frequency and that stale, expired, or unused rules are removed.
Test Confirm boundary protection devices fail to a deny (closed) state on component failure or overload, so a device fault does not expose internal networks.
Examine Verify boundary device logs are forwarded to centralized monitoring/SIEM and that alerting is configured for anomalous or policy-violating cross-boundary traffic (CIS Control 13).