adammontville / cis-controls-71-measures

0 stars 0 forks source link

Subcontrol 12.4 #21

Open adammontville opened 5 years ago

adammontville commented 5 years ago

Deny communication over unauthorized TCP or UDP ports or application traffic to ensure that only authorized protocols are allowed to cross the network boundary in or out of the network at each of the organization's network boundaries.

Measures

# of total unauthorized TCP/UDP ports(using formal analytics) = M1 = 2 * SUM from ๐‘–=1 to n(# ๐‘œ๐‘“ ๐‘ข๐‘›๐‘Ž๐‘ข๐‘กโ„Ž๐‘œ๐‘Ÿ๐‘–๐‘ง๐‘’๐‘‘ ๐‘๐‘œ๐‘Ÿ๐‘ก ๐‘–๐‘› ๐‘๐‘œ๐‘ข๐‘›๐‘‘๐‘Ž๐‘Ÿ๐‘ฆ ๐‘‘๐‘’๐‘ฃ๐‘–๐‘๐‘’ ๐‘–)
M2= # of sent unique(in terms of port and device) probe
M3 = # of total unauthorized TCP/UDP ports(using formal analytics)
M4 = #of detected traffic to unauthorized TCP/UDP port
# of whitelisted application

Metrics/KEI

Measuring the detectability of connections to unauthorized TCP or UDP ports Coverage = M2/ M3
Quality Measure(Detectability) =M4/M3
Same as TCP/UDP port

This seems like a simple configuration measure.

wmunyan commented 5 years ago

Very similar to 9.4

Inputs:

Operations:

Measures:

Metrics:

??

adammontville commented 5 years ago

Inputs:

Operations:

Measures:

Metrics: