NIST SP 800-171 & CMMC 2.0 Control 3.13.1 Requirement:

Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.

NIST SP 800-171 & CMMC 2.0 3.13.1 Requirement Explanation:

The goal of this control is to protect your systems from network-based attacks using firewalls. To do this firewalls separate your company's networks from attackers. Firewalls also control the traffic allowed across your network. These two features prevent and limit the effectiveness of network-based attacks.

Example NIST SP 800-171 & CMMC 2.0 3.13.1 Implementation:

Deploy a firewall between your company network and the internet. Configure your firewall to only allow authorized traffic to enter and exit your network. Use a web proxy to block access to malicious websites. Achieve this by blocking unnecessary services and ports. If you have several internal networks, deploy a firewall between them. Only allow necessary traffic between your networks. Create a network diagram that displays your information system boundary.

NIST SP 800-171 & CMMC 2.0 3.13.1 Scenario(s):

- Scenario 1:

Alice is a system administrator at a small company. She configures the firewall on her router to only allow HTTP and HTTPS traffic to exit her network. She also configures it to block gambling, pornographic, and malicious sites. Alice is now monitoring, controlling, and protecting her company's network communications.

