home/glossary/filtering rule

filtering rule

nounid 163603·updated Sep 1, 2026
verified

A policy-enforcement construct used in network security devices—routers, firewalls, and analogous boundary-protection components—that specifies a set of match conditions (such as source and destination address, protocol, and port) paired with a disposition (permit or deny) to be applied to traffic meeting those conditions. To apply a filtering process, a device is configured with a set of filtering rules, where each rule specifies a decision (e.g., accept or deny) that applies to a set of condition attributes such as protocol, source, destination, and so on. Rules are evaluated against each packet or flow, typically in ordered sequence, and together they constitute the operative expression of the organization's traffic-control policy. In standards usage (NIST SP 800-53 and SP 800-171), filtering rules for routers or firewalls are classified as security-relevant information alongside cryptographic key management data and access control lists.

MWE

Source

document
NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems
found in
proposed during MWE review
element
e0198
proposed by
dorianc@moxywolf.com
discovery
ManualCuration
, filtering rules for routers or firewalls,the sentence this term was read in
Where the definition came fromawaiting curator confirmation

generalized from a web lookup of the quoted expression at proposal time Verdict: term of art.

A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.

A web lookup ran when this term was proposed

A network access-control directive configured on a boundary device — such as a firewall or router — that specifies a set of condition attributes (protocol, source address, destination address, port, etc.) together with a decision (accept or deny) to be applied to traffic matching those conditions. It operationalizes an organization's information-flow control policy by restricting traffic between designated sources and destinations, enforced in boundary protection devices through rule sets that may provide packet-filtering capability based on header information or message-filtering capability based on content. Rules are evaluated sequentially against each incoming packet — the first matching rule's action is applied, and if no rule matches the packet is typically rejected — making rule ordering a security-critical property of the overall policy. Standards bodies such as NIST treat filtering rules for routers or firewalls as security-relevant information warranting protection in their own right, placing them alongside cryptographic key material and access control lists.

Advisory only. A term this product ships is defined by an authority document, not by a search result.

Proposed during multiword review of this document in the CKI mapping queue.

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems1 citation · 1 confirmed by a reviewer · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
03.01.05.d ¶ 1

Classifications

Entity Type

Requirement85%manual reviewllm:claude-haiku-4-5

Sensitivity

Regulated88%manual reviewllm:claude-haiku-4-5

Information Class

78%llm-generatedmulti_axis_classifier_queued.v1

Variants

plural
filtering rules
possessive
filtering rule's
pluralpossessive
filtering rules'

Framework definitions

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
A policy-enforcement construct used in network security devices—routers, firewalls, and analogous boundary-protection components—that specifies a set of match conditions (such as source and destination address, protocol, and port) paired with a disposition (permit or deny) to be applied to traffic meeting those conditions. To apply a filtering process, a device is configured with a set of filtering rules, where each rule specifies a decision (e.g., accept or deny) that applies to a set of condition attributes such as protocol, source, destination, and so on. Rules are evaluated against each packet or flow, typically in ordered sequence, and together they constitute the operative expression of the organization's traffic-control policy. In standards usage (NIST SP 800-53 and SP 800-171), filtering rules for routers or firewalls are classified as security-relevant information alongside cryptographic key management data and access control lists.
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.