filtering rule
163603·updated Sep 1, 2026A policy-enforcement construct used in network security devices—routers, firewalls, and analogous boundary-protection components—that specifies a set of match conditions (such as source and destination address, protocol, and port) paired with a disposition (permit or deny) to be applied to traffic meeting those conditions. To apply a filtering process, a device is configured with a set of filtering rules, where each rule specifies a decision (e.g., accept or deny) that applies to a set of condition attributes such as protocol, source, destination, and so on. Rules are evaluated against each packet or flow, typically in ordered sequence, and together they constitute the operative expression of the organization's traffic-control policy. In standards usage (NIST SP 800-53 and SP 800-171), filtering rules for routers or firewalls are classified as security-relevant information alongside cryptographic key management data and access control lists.
Source
, filtering rules for routers or firewalls,the sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: term of art.
- Misconfiguration Management of Network Security Components
- CHAPTER THREE PAGE 1 ACCESS CONTROL Quick link to Access Control summary table
- NIST Special Publication 800 NIST SP 800-171r3
- Algorithms for Analysing Firewall and Router Access Lists
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
A network access-control directive configured on a boundary device — such as a firewall or router — that specifies a set of condition attributes (protocol, source address, destination address, port, etc.) together with a decision (accept or deny) to be applied to traffic matching those conditions. It operationalizes an organization's information-flow control policy by restricting traffic between designated sources and destinations, enforced in boundary protection devices through rule sets that may provide packet-filtering capability based on header information or message-filtering capability based on content. Rules are evaluated sequentially against each incoming packet — the first matching rule's action is applied, and if no rule matches the packet is typically rejected — making rule ordering a security-critical property of the overall policy. Standards bodies such as NIST treat filtering rules for routers or firewalls as security-relevant information warranting protection in their own right, placing them alongside cryptographic key material and access control lists.
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- filtering rules
- possessive
- filtering rule's
- pluralpossessive
- filtering rules'
Framework definitions
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A policy-enforcement construct used in network security devices—routers, firewalls, and analogous boundary-protection components—that specifies a set of match conditions (such as source and destination address, protocol, and port) paired with a disposition (permit or deny) to be applied to traffic meeting those conditions. To apply a filtering process, a device is configured with a set of filtering rules, where each rule specifies a decision (e.g., accept or deny) that applies to a set of condition attributes such as protocol, source, destination, and so on. Rules are evaluated against each packet or flow, typically in ordered sequence, and together they constitute the operative expression of the organization's traffic-control policy. In standards usage (NIST SP 800-53 and SP 800-171), filtering rules for routers or firewalls are classified as security-relevant information alongside cryptographic key management data and access control lists.DR-088 backfill from the noun definition column