home/dictionary/external communications traffic

external communications traffic

nounverified·updated Aug 30, 2026

Network data flows—packets, sessions, and protocol exchanges—that cross an organizational boundary, moving between an internal network and an external one (typically the public internet or a third-party network). It is distinguished from purely internal traffic by its traversal of a managed interface such as a firewall, gateway, or proxy, where boundary-protection controls are applied: enforcing traffic-flow policies, blocking spoofed-source packets, filtering unauthorized protocols, and preventing cleartext transmission of sensitive data. In NIST SP 800-53 (SC-7), boundary protection is framed around monitoring and controlling communications at the external boundary through managed interfaces—gateways, routers, firewalls, and similar devices—that sit between internal organizational networks and external networks. NIST SP 800-171 (§ 3.13.1) uses the concept operationally, for example by restricting external web communications traffic to designated web servers and prohibiting traffic that appears to spoof internal addresses. CIS Control 12 (Boundary Defense) similarly directs organizations to control the flow of traffic through network borders using firewalls, proxies, DMZ perimeter

Framework senses

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
Network data flows—packets, sessions, and protocol exchanges—that cross an organizational boundary, moving between an internal network and an external one (typically the public internet or a third-party network). It is distinguished from purely internal traffic by its traversal of a managed interface such as a firewall, gateway, or proxy, where boundary-protection controls are applied: enforcing traffic-flow policies, blocking spoofed-source packets, filtering unauthorized protocols, and preventing cleartext transmission of sensitive data. In NIST SP 800-53 (SC-7), boundary protection is framed around monitoring and controlling communications at the external boundary through managed interfaces—gateways, routers, firewalls, and similar devices—that sit between internal organizational networks and external networks. NIST SP 800-171 (§ 3.13.1) uses the concept operationally, for example by restricting external web communications traffic to designated web servers and prohibiting traffic that appears to spoof internal addresses. CIS Control 12 (Boundary Defense) similarly directs organizations to control the flow of traffic through network borders using firewalls, proxies, DMZ perimeter
DR-088 backfill from the noun definition column