π‘οΈπͺπ»ππβοΈGroup - DMA Guard Allowed
What this group is forβ
This is a static assigned device group that carves an exception out of the tenant-wide block on external DMA.
It works only as a pair with:
- π§±πͺπ»ES - DMA Guard: the default block this group is excluded from.
- π§±πͺπ»πES - DMA Guard - Allow: the inverse policy assigned to this group, which reopens DMA.
A device in this group is dropped from the block and actively allowed external DMA again. Membership is an exception with a hardware reason, not a convenience.
π οΈ Group Configurationβ
| Setting | Value |
|---|---|
| Group name | π‘οΈπͺπ»ππβοΈGroup - DMA Guard Allowed |
| Group description | Devices explicitly allowed external DMA, overriding the DMA Guard block, because they run a peripheral that lacks memory remapping. Membership requires documented, approved justification. |
| Group type | Security |
| Membership type | Assigned (Device Group) |
β οΈ Governanceβ
Excluding a device from the block is only half the job; the inverse policy is what actually reopens DMA, so both assignments must be in place. And because you are reopening a physical attack surface, the bar is high:
- A documented peripheral requirement per device (which dock, which card, why).
- Written risk acceptance from the customer.
- A regular membership review (quarterly at least), and ideally physical control of the device.
Good reason: a fixed workstation with an older capture card that has no remapping support. Bad reason: "the dock was acting up, so I allowed everything." If you cannot defend a device's place here in an audit, it does not belong here.
π Relatedβ
Keep it small. An exception group the size of the fleet is not an exception, it is a disarmed defense wearing a disguise. π