Partial implementation supportHigh confidence
Why: The practice's deployed state is inter-zone default-deny: traffic between zones is refused unless a reviewed rule permits it, which is precisely the deny-all, permit-by-exception posture this requirement names.
What this does not claim: The requirement applies to network communications traffic generally — including the external perimeter and egress — while the practice enforces the posture between internal zones. Hosts within a single zone still communicate freely unless host-level policy extends the model, and every permit rule needs a recorded justification for the by-exception framing to survive an assessor's sampling.
Practice-side activities- Convert discovered traffic into explicit allow rules with owners, then flip the inter-zone default to deny
- Review the rulebase on a cadence and expire broad allows
Evidence this produces- Rule exports showing default-deny between zones
- Rule review records with per-exception justifications
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06
Partial implementation supportModerate confidence
Why: Deny-by-default with permit-by-exception is the traffic policy strict OT segmentation enforces at the IT/OT boundary and between zones — the practice's mature state is this requirement's posture, applied to the plant. Mirrors the corrected Rev. 2 relationship (3.13.6).
What this does not claim: May partially address the requirement, and only for OT components within the assessed CUI boundary — organizational scoping determines applicability. The requirement spans the whole system's network communications including the IT estate, and deny-by-default on a live control network is reached incrementally through permit-and-log observation and planned windows, because a missed permit rule can stop production or sever a safety-relevant flow.
Practice-side activities- Move boundary and conduit rules to default-deny with a documented, dated exception list
- Learn legitimate plant traffic in permit-and-log mode before enforcing
- Tighten in planned maintenance windows with process-owner sign-off and rollback
Evidence this produces- Rule exports showing deny-by-default with justified exceptions
- The exception list with owners and expiry dates
- Staged-enforcement change records with safety review
Where this holds: Holds for OT zones and conduits inside the assessed boundary; the requirement's enterprise scope needs separate treatment.
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06