Anti-Spoofing Policy
Version 2.0
For Students, Faculty, Staff, Guests, Alumni
Purpose
The purpose of this policy is to ensure that anti-spoofing measures are in place to detect and block network traffic that uses forged, invalid, or unauthorized source IP addresses connecting to the University network.
Scope
This IT security policy, and all policies referenced herein, shall apply to all members of the University community, including faculty, students, administrative officials, staff, alumni, authorized guests, delegates, and independent contractors (the “User(s)” or “you”) who use, access, or otherwise employ, locally or remotely, the University’s IT Resources, whether individually controlled, shared, stand-alone, or networked.
Policy Statement
- Network devices must reject inbound packets originating from external networks when the source address claims to originate from Fordham University-owned or managed address space.
- Applicable IT Resources must use source address validation or equivalent filtering to restrict traffic with invalid, unauthorized, or spoofed source addresses, including outbound traffic using source addresses that are not assigned or authorized for the originating University network.
- Anti-spoofing controls must be implemented on managed interfaces using approved configurations appropriate to the network architecture. Controls may include access control lists, routing validation features, or other source address validation mechanisms.
- Anti-spoofing and boundary protection configurations must be maintained through approved configuration and change management processes and reviewed periodically to reflect changes in the University network addressing and architecture.
- Where supported, events indicating suspected source address spoofing or attempted bypass of anti-spoofing controls must be logged or monitored and handled in accordance with University incident response procedures.
Definitions
IT Resources include computing, networking, communications, application, and telecommunications systems, infrastructure, hardware, software, data, databases, personnel, procedures, physical facilities, cloud-based vendors, Software as a Service (SaaS) vendors, and related materials and services.
Spoofing is the falsification of a network packet’s source IP address so that traffic appears to originate from a different, often trusted, system or network.
NIST SP 800-53 Rev. 5 Alignment
- System and Communications Protection: SC-1 Policy and Procedures; SC-7 Boundary Protection; SC-7(9) Restrict Threatening Outgoing Communications Traffic; SC-7(11) Restrict Incoming Communications Traffic.
- Configuration Management: CM-6 Configuration Settings.
- System and Information Integrity: SI-4 System Monitoring.
Related Policies and Procedures
- Firewall/Network Access Control List Policy
- PCI Network Protocol
- Logging Requirements Policy
- Information Security Incident Response Policy
Implementation Information
| Review Frequency: | Triennial |
|---|---|
| Responsible Person: | Senior Director of IT Security and Assurance |
| Approved By: | CISO |
| Approval Date: | March 1, 2017 |
Revision History
| Version: | Date: | Description: |
|---|---|---|
| 1.0 | 03/01/2017 | Initial document |
| 1.0.1 | 05/22/2019 | Updated policy statement and related policy links |
| 1.2 | 06/02/2020 | Updated policy statement and definitions |
| 1.3 | 07/31/2023 | Updated policy statement, scope, disclaimer |
| 2.0 | 08/31/2026 | Substantive revision strengthened anti-spoofing and boundary protection requirements; added source address validation, outbound filtering, configuration review, and monitoring requirements; aligned with NIST SP 800-53 Rev. 5 controls SC-1, SC-7, SC-7(9), SC-7(11), CM-6, and SI-4. |
Policy Disclaimer Statement
Deviations from policies, procedures, or guidelines published and approved by Information Security and Assurance (ISA) will only be considered cooperatively between ISA and the requesting entity with sufficient notice to allow for conducting appropriate risk analysis, documentation, review, and notification to authorized University representatives where necessary. Failure to adhere to ISA written policies may be met with University sanctions up to and including dismissal.