Perimeter Defense Sample Clauses
Perimeter Defense. A. Any individual connecting an SVHC network device to a public network is required to deploy a firewall or similar perimeter defense system.
B. Firewall devices must be configured to grant access to the SVHC network based on least privilege / minimum necessary information requirements.
C. Periodic maintenance and review of firewall configurations (including rule sets) and vulnerability testing must be conducted to ensure continued protection.
D. Any individual with a non-owned/non-supported device, or modality, is prohibited from attaching to an SVHC network port or wireless access point without proper authorization from Senior IT Management.
E. Once deployed, firewall device access logs must remain on file for an appropriate pre-determined timeframe and be reviewed on a periodic basis.
F. With the exception of authorized security testing, any attempt to circumvent the SVHC firewalls or other perimeter defenses is prohibited.
