
Appendix L: Gap Analysis Examples ◾ 379
11.4.4 Remote
Diagnostic and
Configuration
Port Protection
Physical and logical access to
diagnostic and configuration ports
should be controlled.
11.4.5
Segregation in
Networks
Groups of information services, users,
and information systems should be
segregated on networks.
1.1.4
Description of the groups,
roles, and responsibilities
standards must be
implemented.
11.4.6
Network
Connection
Control
For shared networks, especially those
extending across the organization’s
boundaries, the capability of users to
connect to the network should be
restricted, in line with the access
control policy and requirements ...