data.gift
  • Datasets

http://cyfun.data.gift/data/requirement_PR_IR_01_5

http://cyfun.data.gift/data/requirement_PR_IR_01_5
Concept

  • http://cyfun.data.gift/data/CyFun2025

    • External link
    • Internal link
  • http://cyfun.data.gift/data/CyFun2025_delta_IMPORTANT_to_ESSENTIAL

    • External link
    • Internal link
  • http://cyfun.data.gift/data/CyFun2025_ESSENTIAL

    • External link
    • Internal link

  • http://cyfun.data.gift/data/subcategory_PR.IR-01

    • External link
    • Internal link

Properties and relations

Direct links from the subject.

Property Value

type

The subject is an instance of a class.

  • External link
  • Internal link

http://cyfun.data.gift/ontology#Requirement

  • External link
  • Internal link

type

The subject is an instance of a class.

  • External link
  • Internal link

Concept

An idea or notion; a unit of thought.

  • External link
  • Internal link

label

A human-readable name for the subject.

  • External link
  • Internal link

PR.IR-01.5: The organisation shall implement, where feasible, authenticated proxy servers or fire- walls with URL filtering and threat intelligence capabilities for defined communications traffic between its critical systems and external networks.

http://cyfun.data.gift/ontology#requirementId

  • External link
  • Internal link

PR.IR-01.5

http://cyfun.data.gift/ontology#foundIn

  • External link
  • Internal link

http://cyfun.data.gift/data/loc_CyFun2025_Booklet_ESSENTIAL_E_p134

  • External link
  • Internal link

has broader

Relates a concept to a concept that is more general in meaning.

  • External link
  • Internal link

http://cyfun.data.gift/data/subcategory_PR.IR-01

  • External link
  • Internal link

note

A general note, for any purpose.

  • External link
  • Internal link

The goal of this control is to reduce the risk of cyber threats entering critical systems, by filtering and inspecting outbound and inbound communications through authenticated proxies or firewalls. To achieve this goal, the following should be considered: - Access Controls Proxy servers and firewalls should enforce strict access controls, allowing only authorised users and systems. Strong authentication methods, such as multi-factor authentication (MFA), should be used to support zero- trust principles. - Encryption Communications between clients and proxyservers should be encrypted using the most current and secure versions of SSL/TLS to protect against eavesdropping and man-in-the-middle attacks. - Threat Intelligence and URL Filtering - To effectively monitor and control communications across IT and OT environments, proxy servers and firewalls should: - Integrate threat intelligence feeds to detect and block known malicious domains, IPaddresses, and URLs. - Apply URL filtering to prevent access to harmful or unauthorised web content. - In OT environments, where systems often lack built-in security features, intelligent filtering at network boundaries should be used to: - Detect and block malicious traffic before it reaches critical systems. - Prevent data exfiltration and unauthorised external communication. - Enforce communication policies without disrupting operational processes. These measures should be part of a layered defence strategy that supports secure and reliable operations across both IT and OT domains. - Logging and Monitoring Detailed logging and continuous monitoring should be enabled to track access, detect anomalies, and support incident response. Logs should be regularly reviewed for signs of compromise. - Firewall Configuration Firewalls should be configured to allow only explicitly authorised traffic to and from proxy servers. A “deny by default” policy should be enforced. - Regular Updates and Patching Proxy servers, firewalls, and their underlying systems should be regularly updated and patched to address known vulnerabilities and maintain security effectiveness. - Performance and Reliability Load balancing should be used to distribute traffic across multiple proxy servers or firewalls, ensuring high availability and optimal performance. Resource usage should be monitored to prevent overload and degradation.

note

A general note, for any purpose.

  • External link
  • Internal link

The goal of this control is to reduce the risk of cyber threats entering critical systems, by filtering and inspecting outbound and inbound communications through authenticated proxies or firewalls. To achieve this goal, the following should be considered: - Access Controls Proxy servers and firewalls should enforce strict access controls, allowing only authorised users and systems. Strong authentication methods, such as multi-factor authentication (MFA), should be used to support zero- trust principles. - Encryption Communications between clients and proxyservers should be encrypted using the most current and secure versions of SSL/TLS to protect against eavesdropping and man-in-the-middle attacks. - Threat Intelligence and URL Filtering - To effectively monitor and control communications across IT and OT environments, proxy servers and firewalls should: - Integrate threat intelligence feeds to detect and block known malicious domains, IPaddresses, and URLs. - Apply URL filtering to prevent access to harmful or unauthorised web content. - In OT environments, where systems often lack built-in security features, intelligent filtering at network boundaries should be used to: - Detect and block malicious traffic before it reaches critical systems. - Prevent data exfiltration and unauthorised external communication. - Enforce communication policies without disrupting operational processes. These measures should be part of a layered defence strategy that supports secure and reliable operations across both IT and OT domains. - Logging and Monitoring Detailed logging and continuous monitoring should be enabled to track access, detect anomalies, and support incident response. Logs should be regularly reviewed for signs of compromise. - Firewall Configuration Firewalls should be configured to allow only explicitly authorised traffic to and from proxy servers. A “deny by default” policy should be enforced. - Regular Updates and Patching Proxy servers, firewalls, and their underlying systems should be regularly updated and patched to address known vulnerabilities and maintain security effectiveness. - Performance and Reliability Load balancing should be used to distribute traffic across multiple proxy servers or firewalls, ensuring high availability and optimal performance. Resource usage should be monitored to prevent overload and degradation.

note

A general note, for any purpose.

  • External link
  • Internal link

<div><p>The goal of this control is to reduce the risk of cyber threats entering critical systems, by filtering and inspecting outbound and inbound communications through authenticated proxies or firewalls. To achieve this goal, the following should be considered:</p><ul><li>Access Controls Proxy servers and firewalls should enforce strict access controls, allowing only authorised users and systems. Strong authentication methods, such as multi-factor authentication (MFA), should be used to support zero- trust principles.</li><li>Encryption Communications between clients and proxyservers should be encrypted using the most current and secure versions of SSL/TLS to protect against eavesdropping and man-in-the-middle attacks.</li><li>Threat Intelligence and URL Filtering<ul><li>To effectively monitor and control communications across IT and OT environments, proxy servers and firewalls should:<ul><li>Integrate threat intelligence feeds to detect and block known malicious domains, IPaddresses, and URLs.</li><li>Apply URL filtering to prevent access to harmful or unauthorised web content.</li></ul></li><li>In OT environments, where systems often lack built-in security features, intelligent filtering at network boundaries should be used to:<ul><li>Detect and block malicious traffic before it reaches critical systems.</li><li>Prevent data exfiltration and unauthorised external communication.</li><li>Enforce communication policies without disrupting operational processes. These measures should be part of a layered defence strategy that supports secure and reliable operations across both IT and OT domains.</li></ul></li></ul></li><li>Logging and Monitoring Detailed logging and continuous monitoring should be enabled to track access, detect anomalies, and support incident response. Logs should be regularly reviewed for signs of compromise.</li><li>Firewall Configuration Firewalls should be configured to allow only explicitly authorised traffic to and from proxy servers. A “deny by default” policy should be enforced.</li><li>Regular Updates and Patching Proxy servers, firewalls, and their underlying systems should be regularly updated and patched to address known vulnerabilities and maintain security effectiveness.</li><li>Performance and Reliability Load balancing should be used to distribute traffic across multiple proxy servers or firewalls, ensuring high availability and optimal performance. Resource usage should be monitored to prevent overload and degradation.</li></ul></div>

note

A general note, for any purpose.

  • External link
  • Internal link

The goal of this control is to reduce the risk of cyber threats entering critical systems, by filtering and inspecting outbound and inbound communications through authenticated proxies or firewalls. To achieve this goal, the following should be considered: • Access Controls Proxy servers and firewalls should enforce strict access controls, allowing only authorised users and systems. Strong authentication methods, such as multi-factor authentication (MFA), should be used to support zero- trust principles. • Encryption Communications between clients and proxyservers should be encrypted using the most current and secure versions of SSL/TLS to protect against eavesdropping and man-in-the-middle attacks. • Threat Intelligence and URL Filtering o To effectively monitor and control communications across IT and OT environments, proxy servers and firewalls should: - Integrate threat intelligence feeds to detect and block known malicious domains, IPaddresses, and URLs. - Apply URL filtering to prevent access to harmful or unauthorised web content. o In OT environments, where systems often lack built-in security features, intelligent filtering at network boundaries should be used to: - Detect and block malicious traffic before it reaches critical systems. - Prevent data exfiltration and unauthorised external communication. - Enforce communication policies without disrupting operational processes. These measures should be part of a layered defence strategy that supports secure and reliable operations across both IT and OT domains. • Logging and Monitoring Detailed logging and continuous monitoring should be enabled to track access, detect anomalies, and support incident response. Logs should be regularly reviewed for signs of compromise. • Firewall Configuration Firewalls should be configured to allow only explicitly authorised traffic to and from proxy servers. A “deny by default” policy should be enforced. • Regular Updates and Patching Proxy servers, firewalls, and their underlying systems should be regularly updated and patched to address known vulnerabilities and maintain security effectiveness. • Performance and Reliability Load balancing should be used to distribute traffic across multiple proxy servers or firewalls, ensuring high availability and optimal performance. Resource usage should be monitored to prevent overload and degradation.

notation

A notation, also known as classification code, is a string of characters such as "T58.5" or "303.4833" used to uniquely identify a concept within the scope of a given concept scheme.

  • External link
  • Internal link

PR.IR-01.5

alternative label

skos:prefLabel, skos:altLabel and skos:hiddenLabel are pairwise disjoint properties.

  • External link
  • Internal link

Authenticated proxy and URL filtering

preferred label

A resource has no more than one value of skos:prefLabel per language tag, and no more than one value of skos:prefLabel without language tag.

  • External link
  • Internal link

The organisation shall implement, where feasible, authenticated proxy servers or fire- walls with URL filtering and threat intelligence capabilities for defined communications traffic between its critical systems and external networks.

is in scheme

Relates a resource (for example a concept) to a concept scheme in which it is included.

  • External link
  • Internal link

http://cyfun.data.gift/data/CyFun2025

  • External link
  • Internal link

is in scheme

Relates a resource (for example a concept) to a concept scheme in which it is included.

  • External link
  • Internal link

http://cyfun.data.gift/data/CyFun2025_delta_IMPORTANT_to_ESSENTIAL

  • External link
  • Internal link

is in scheme

Relates a resource (for example a concept) to a concept scheme in which it is included.

  • External link
  • Internal link

http://cyfun.data.gift/data/CyFun2025_ESSENTIAL

  • External link
  • Internal link

http://cyfun.data.gift/ontology#level

  • External link
  • Internal link

http://cyfun.data.gift/data/level_ESSENTIAL

  • External link
  • Internal link

triple count

The number of triples associated with the subject.

  • External link
  • Internal link

17

in dataset

Specifies the dataset the subject is part of.

  • External link
  • Internal link

http://data.gift/d/datasets/69E8863AA6CE46D9ACD13109

  • External link
  • Internal link

Resultaten 1 - 19 of 19

References

Inverse links to the subject.

Property Subject

http://cyfun.data.gift/ontology#hasRequirement

  • External link
  • Internal link

http://cyfun.data.gift/data/subcategory_PR.IR-01

  • External link
  • Internal link

has narrower

Relates a concept to a concept that is more specific in meaning.

  • External link
  • Internal link

http://cyfun.data.gift/data/subcategory_PR.IR-01

  • External link
  • Internal link

Resultaten 1 - 1 of 1

© 2024 redpencil.io. All rights reserved.