Print This Page
White Listing
"Whitelisting is a form of filtering where a list is created that registers entities that are granted access or are welcomed signatures. When a whitelist is used, the default is to ""deny all"" except for those entries that are enumerated in the filter. These are typically used when it is easier (or a shorter list) to identify what is desirable rather than what is not desirable. "
Cloud Controls Matrix (CCM) Data
SA-15 | Security Architecture | Mobile Code
Control Specification +-
Mobile code shall be authorized before its installation and use, and the configuration shall ensure that the authorized mobile code operates according to a clearly defined security policy. All unauthorized mobile code shall be prevented from executing.
Architectural Relevance +-
Physical | Network | Compute | App | Data |
---|
False
| True
| True
| False
| True
|
Corp Gov Relevance +-
Cloud Service Delivery Model Applicability +-
SaaS | PaaS | IaaS |
---|
True
| True
| True
|
Supplier Relationship +-
Service Provider | Tenant / Consumer |
---|
True
| True
|
Scope Applicability +-
COBIT 4.1 | HIPAA / HITECH Act | ISO/IEC 27001-2005 |
---|
|
| A.10.4.2
A.12.2.2
|
NIST SP800-53 R3 | FedRAMP (Final 2012) Low Impact | FedRAMP (Final 2012) Moderate Impact | PCI DSS v2.0 |
---|
SC-18
|
|
|
|
BITS Shared Assessments SIG v6.0 | BITS Shared Assessments SIG v5.0 | GAPP (Aug 2009) |
---|
G.20.12, I.2.5
|
|
|
Jericho Forum | NERC CIP |
---|
Commandment #1
Commandment #2
Commandment #3
Commandment #5
Commandment #11
|
|
Consensus Assessments Initiative Questionnaire (CAIQ) Data
Is mobile code authorized before its installation and use and the code configuration checked to ensure that the authorized mobile code operates according to a clearly defined security policy?
Compliance Mapping +-
COBIT | HIPAA | ISO27001 | SP800_53 |
---|
|
| A.10.4.2
A.12.2.2
| NIST SP800-53 R3 SC-18
|
FedRAMP | PCI_DSS | BITS | GAPP |
---|
NIST SP800-53 R3 SC-18
NIST SP800-53 R3 SC-18 (4)
|
| SIG v6.0:G.20.12, I.2.5
|
|
Model Applicability +-
SaaS | PaaS | IaaS |
---|
True
| True
| True
|
Scope Applicability +-