Skip to main content

Networking / Loadbalancer / Controls / DEV

Enforce Distribution Policies

CCC.LB.CN04 · Access

Ensure traffic-splitting weights and algorithms are modified only by trusted identities.

Related Capabilities

IDTitleDescription
CCC.LB.CP02Dynamic Load BalancingEmploy load balancing algorithms that consider the current state of servers before distributing traffic. Load balancer adjusts traffic distribution in real-time based on the current server health, resource utilization, and traffic conditions.
CCC.LB.CP20Traffic Splitting / Weighted RoutingCan distribute incoming traffic across multiple backend resources based on predefined weights or percentages (e.g., for canary deployments, A/B testing, blue-green deployments, or gradual traffic migrations).

Related Threats

IDTitleDescription
CCC.LB.TH03Traffic Distribution Is ManipulatedAdjusting distribution policies can concentrate traffic on specific nodes causing DoS or redirect flows through unwanted paths.

Assessment Requirements

IDTextApplicability
CCC.LB.CN04.AR01When routing weights change, the request MUST originate from an explicitly defined and trusted identity and MUST be logged.tlp-green, tlp-amber, tlp-red

Guideline Mappings

FrameworkIDRemarks
NIST-CSFPR.AC-1Identities and credentials are managed
NIST_800_53AC-3Access enforcement