filtering rule
A policy-enforcement construct used in network security devices—routers, firewalls, and analogous boundary-protection components—that specifies a set of match conditions (such as source and destination address, protocol, and port) paired with a disposition (permit or deny) to be applied to traffic meeting those conditions. To apply a filtering process, a device is configured with a set of filtering rules, where each rule specifies a decision (e.g., accept or deny) that applies to a set of condition attributes such as protocol, source, destination, and so on. Rules are evaluated against each packet or flow, typically in ordered sequence, and together they constitute the operative expression of the organization's traffic-control policy. In standards usage (NIST SP 800-53 and SP 800-171), filtering rules for routers or firewalls are classified as security-relevant information alongside cryptographic key management data and access control lists.
Framework senses
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A policy-enforcement construct used in network security devices—routers, firewalls, and analogous boundary-protection components—that specifies a set of match conditions (such as source and destination address, protocol, and port) paired with a disposition (permit or deny) to be applied to traffic meeting those conditions. To apply a filtering process, a device is configured with a set of filtering rules, where each rule specifies a decision (e.g., accept or deny) that applies to a set of condition attributes such as protocol, source, destination, and so on. Rules are evaluated against each packet or flow, typically in ordered sequence, and together they constitute the operative expression of the organization's traffic-control policy. In standards usage (NIST SP 800-53 and SP 800-171), filtering rules for routers or firewalls are classified as security-relevant information alongside cryptographic key management data and access control lists.DR-088 backfill from the noun definition column