Skip to main content

CCC.Build.C03: Deny External Network Access for Build Environments

Control ID:CCC.Build.C03
Title:Deny External Network Access for Build Environments
Objective:Ensure that build environments do not have external network access to prevent unauthorized external access and data exfiltration.
Control Family:
Network Security

Related Threats

IDTitleDescriptionExternal MappingsCapability MappingsControl Mappings
CCC.Core.TH02Data is Intercepted in TransitData transmitted by the service is susceptible to collection by any entity with access to any part of the transmission path. Packet observations can be used to support the planning of attacks by profiling origin points, destinations, and usage patterns. The data may also be vulnerable to interception or modification in transit if not properly encrypted, impacting the confidentiality or integrity of the transmitted data.
1
1
0
CCC.Core.TH05Interference with Replication ProcessesMisconfigured or manipulated replication processes may lead to data being copied to unintended locations, delayed, modified, or not being copied at all. This could lead to compromised data confidentiality and integrity, potentially also affecting recovery processes and data availability.
1
1
0

Guideline Mappings

Reference IDEntry IDStrengthRemarks
NIST-CSF
PR.AC-5
0
-
NIST_800_53
SC-7
0
-
NIST_800_53
SC-5
0
-

Assessment Requirements

IDDescriptionApplicability
CCC.Build.C03.TR01Attempt to access the build environment from an external network and verify that access is denied.
tlp-red
tlp-amber