Control Objectives: Network
No control objectives match the current filters.
12.1 Ensure Network Infrastructure is Up-to-Date
SNow
Classification: ProtectState: Published
Ensure network infrastructure is kept up-to-date. Example implementations include running the latest stable release of software and/or using currently supported network-as-a-service (NaaS) offerings. Review software versions monthly, or more frequently, to verify software support.
12.2 Establish and Maintain a Secure Network Architecture
SNow
Classification: ProtectState: Published
Establish and maintain a secure network architecture. A secure network architecture must address segmentation, least privilege, and availability, at a minimum.
12.3 Securely Manage Network Infrastructure
SNow
Classification: ProtectState: Published
Securely manage network infrastructure. Example implementations include version-controlled-infrastructure-as-code, and the use of secure network protocols, such as SSH and HTTPS.
12.4 Establish and Maintain Architecture Diagram(s)
SNow
Classification: IdentifyState: Published
Establish and maintain architecture diagram(s) and/or other network system documentation. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
12.5 Centralize Network Authentication, Authorization, and Auditing (AAA)
SNow
Classification: ProtectState: Published
Centralize network AAA.
12.6 Use of Secure Network Management and Communication Protocols
SNow
Classification: ProtectState: Published
Use secure network management and communication protocols (e.g., 802.1X, Wi-Fi Protected Access 2 (WPA2) Enterprise or greater).
13.1 Centralize Security Event Alerting
SNow
Classification: DetectState: Published
Centralize security event alerting across enterprise assets for log correlation and analysis. Best practice implementation requires the use of a SIEM, which includes vendor-defined event correlation alerts. A log analytics platform configured with security-relevant correlation alerts also satisfies
13.10 Perform Application Layer Filtering
SNow
Classification: ProtectState: Published
Perform application layer filtering. Example implementations include a filtering proxy, application layer firewall, or gateway.
13.11 Tune Security Event Alerting Thresholds
SNow
Classification: DetectState: Published
Tune security event alerting thresholds monthly, or more frequently.
13.3 Deploy a Network Intrusion Detection Solution
SNow
Classification: DetectState: Published
Deploy a network intrusion detection solution on enterprise assets, where appropriate. Example implementations include the use of a Network Intrusion Detection System (NIDS) or equivalent cloud service provider (CSP) service.
13.4 Perform Traffic Filtering Between Network Segments
SNow
Classification: ProtectState: Published
Perform traffic filtering between network segments, where appropriate.
13.6 Collect Network Traffic Flow Logs
SNow
Classification: DetectState: Published
Collect network traffic flow logs and/or network traffic to review and alert upon from network devices.
13.8 Deploy a Network Intrusion Prevention Solution
SNow
Classification: ProtectState: Published
Deploy a network intrusion prevention solution, where appropriate. Example implementations include the use of a Network Intrusion Prevention System (NIPS) or equivalent CSP service.
18.2 Perform Periodic External Penetration Tests
SNow
Classification: IdentifyState: Published
Perform periodic external penetration tests based on program requirements, no less than annually. External penetration testing must include enterprise and environmental reconnaissance to detect exploitable information. Penetration testing requires specialized skills and experience and must be conduc
Parent
18.3 Remediate Penetration Test Findings
SNow
Classification: ProtectState: Published
Remediate penetration test findings based on the enterprises policy for remediation scope and prioritization.
Parent
18.4 Validate Security Measures
SNow
Classification: ProtectState: Published
Validate security measures after each penetration test. If deemed necessary, modify rulesets and capabilities to detect the techniques used during testing.
Parent
3.12 Segment Data Processing and Storage Based on Sensitivity
SNow
Classification: ProtectState: Published
Segment data processing and storage based on the sensitivity of the data. Do not process sensitive data on enterprise assets intended for lower sensitivity data.
Parent
4.2 Establish and Maintain a Secure Configuration Process for Network Infrastructure
SNow
Classification: ProtectState: Published
Establish and maintain a secure configuration process for network devices. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
4.6 Securely Manage Enterprise Assets and Software
SNow
Classification: ProtectState: Published
Securely manage enterprise assets and software. Example implementations include managing configuration through version-controlled-infrastructure-as-code and accessing administrative interfaces over secure network protocols, such as Secure Shell (SSH) and Hypertext Transfer Protocol Secure (HTTPS). D
8.1 Establish and Maintain an Audit Log Management Process
SNow
Classification: ProtectState: Published
Establish and maintain an audit log management process that defines the enterprises logging requirements. At a minimum, address the collection, review, and retention of audit logs for enterprise assets. Review and update documentation annually, or when significant enterprise changes occur that coul
Parent
8.10 Retain Audit Logs
SNow
Classification: ProtectState: Published
Retain audit logs across enterprise assets for a minimum of 90 days.
Parent
8.11 Conduct Audit Log Reviews
SNow
Classification: DetectState: Published
Conduct reviews of audit logs to detect anomalies or abnormal events that could indicate a potential threat. Conduct reviews on a weekly, or more frequent, basis.
Parent
8.2 Collect Audit Logs
SNow
Classification: DetectState: Published
Collect audit logs. Ensure that logging, per the enterprises audit log management process, has been enabled across enterprise assets.
Parent
8.3 Ensure Adequate Audit Log Storage
SNow
Classification: ProtectState: Published
Ensure that logging destinations maintain adequate storage to comply with the enterprises audit log management process.
Parent
8.4 Standardize Time Synchronization
SNow
Classification: ProtectState: Published
Standardize time synchronization. Configure at least two synchronized time sources across enterprise assets, where supported.
Parent
8.5 Collect Detailed Audit Logs
SNow
Classification: DetectState: Published
Configure detailed audit logging for enterprise assets containing sensitive data. Include event source, date, username, timestamp, source addresses, destination addresses, and other useful elements that could assist in a forensic investigation.
Parent
8.6 Collect DNS Query Audit Logs
SNow
Classification: DetectState: Published
Collect DNS query audit logs on enterprise assets, where appropriate and supported.
Parent
8.7 Collect URL Request Audit Logs
SNow
Classification: DetectState: Published
Collect URL request audit logs on enterprise assets, where appropriate and supported.
Parent
8.9 Centralize Audit Logs
SNow
Classification: DetectState: Published
Centralize, to the extent possible, audit log collection and retention across enterprise assets.
Parent
9.2 Use DNS Filtering Services
SNow
Classification: ProtectState: Published
Use DNS filtering services on all enterprise assets to block access to known malicious domains.
9.3 Maintain and Enforce Network-Based URL Filters
SNow
Classification: ProtectState: Published
Enforce and update network-based URL filters to limit an enterprise asset from connecting to potentially malicious or unapproved websites. Example implementations include category-based filtering, reputation-based filtering, or through the use of block lists. Enforce filters for all enterprise asset
9.5 Implement DMARC
SNow
Classification: ProtectState: Published
To lower the chance of spoofed or modified emails from valid domains, implement DMARC policy and verification, starting with implementing the Sender Policy Framework (SPF) and the DomainKeys Identified Mail (DKIM) standards.
9.6 Block Unnecessary File Types
SNow
Classification: ProtectState: Published
Block unnecessary file types attempting to enter the enterprises email gateway.
9.7 Deploy and Maintain Email Server Anti-Malware Protections
SNow
Classification: ProtectState: Published
Deploy and maintain email server anti-malware protections, such as attachment scanning and/or sandboxing.
Activate audit logging
SNow
Classification: DetectState: Published
Ensure that local logging has been enabled on all systems and networking devices.
Block Unnecessary File Types
SNow
Classification: ProtectState: Published
Block all e-mail attachments entering the organization's e-mail gateway if the file types are unnecessary for the organization's business.
Citations (1)
Boundary Defense
SNow
Classification: IdentifyState: Published
Detect/prevent/correct the flow of information transferring networks of different trust levels with a focus on security-damaging data.
Citations (1)
Children (12)
- Configure Monitoring Systems to Record Network Packets
- Decrypt Network Traffic at Proxy
- Deny Communication over Unauthorized Ports
- Deny Communications with Known Malicious IP Addresses
- Deploy Application Layer Filtering Proxy Server
- Deploy NetFlow Collection on Networking Boundary Devices
- Deploy Network-Based Intrusion Prevention Systems
- Deploy Network-based IDS Sensor
- Maintain an Inventory of Network Boundaries
- Manage All Devices Remotely Logging into Internal Network
- Require All Remote Login to Use Multi-factor Authentication
- Scan for Unauthorized Connections across Trusted Network Bou...
Central Log Management
SNow
Classification: DetectState: Published
Ensure that appropriate logs are being aggregated to a central log management system for analysis and review.
Citations (1)
Configure Monitoring Systems to Record Network Packets
SNow
Classification: DetectState: Published
Configure monitoring systems to record network packets passing through the boundary at each of the organization's network boundaries.
Parent
Controlled Access Based on the Need to Know
SNow
Classification: ProtectState: Published
The processes and tools used to track/control/prevent/correct secure access to critical assets (e.g., information, resources, systems) according to the formal determination of which persons, computers, and applications have a need and right to access these critical assets based on an approved classi
Children (9)
- Disable Workstation to Workstation Communication
- Enable Firewall Filtering Between VLANs
- Encrypt All Sensitive Information in Transit
- Encrypt Sensitive Information at Rest
- Enforce Access Control to Data through Automated Tools
- Enforce Detail Logging for Access or Changes to Sensitive Da...
- Protect Information through Access Control Lists
- Segment the Network Based on Sensitivity
- Utilize an Active Discovery Tool to Identify Sensitive Data
Create Separate Wireless Network for Personal and Untrusted Devices
SNow
Classification: ProtectState: Published
Create a separate wireless network for personal or untrusted devices. Enterprise access from this network should be treated as untrusted and filtered and audited accordingly.
Decrypt Network Traffic at Proxy
SNow
Classification: DetectState: Published
Decrypt all encrypted network traffic at the boundary proxy prior to analyzing the content. However, the organization may use whitelists of allowed sites that can be accessed through the proxy without decrypting the traffic.
Citations (1)
Parent
Deny Communication over Unauthorized Ports
SNow
Classification: ProtectState: Published
Deny communication over unauthorized TCP or UDP ports or application traffic to ensure that only authorized protocols are allowed to cross the network boundary in or out of the network at each of the organization's network boundaries.
Parent
Deny Communications with Known Malicious IP Addresses
SNow
Classification: ProtectState: Published
Deny communications with known malicious or unused Internet IP addresses and limit access only to trusted and necessary IP address ranges at each of the organization's network boundaries,.
Parent
Deploy Application Layer Filtering Proxy Server
SNow
Classification: DetectState: Published
Ensure that all network traffic to or from the Internet passes through an authenticated application layer proxy that is configured to filter unauthorized connections.
Parent
Deploy NetFlow Collection on Networking Boundary Devices
SNow
Classification: DetectState: Published
Enable the collection of NetFlow and logging data on all network boundary devices.
Parent
Deploy Network-Based Intrusion Prevention Systems
SNow
Classification: ProtectState: Published
Deploy network-based Intrusion Prevention Systems (IPS) to block malicious network traffic at each of the organization's network boundaries.
Parent
Deploy Network-based IDS Sensor
SNow
Classification: DetectState: Published
Deploy network-based Intrusion Detection Systems (IDS) sensors to look for unusual attack mechanisms and detect compromise of these systems at each of the organization's network boundaries.
Parent
Deploy SIEM or Log Analytic tool
SNow
Classification: DetectState: Published
Deploy Security Information and Event Management (SIEM) or log analytic tool for log correlation and analysis.
Deploy Web Application Firewalls (WAFs)
SNow
Classification: ProtectState: Published
Protect web applications by deploying web application firewalls (WAFs) that inspect all traffic flowing to the web application for common web application attacks. For applications that are not web-based, specific application firewalls should be deployed if such tools are available for the given appl
Detect Wireless Access Points Connected to the Wired Network
SNow
Classification: DetectState: Published
Configure network vulnerability scanning tools to detect and alert on unauthorized wireless access points connected to the wired network.
Disable Workstation to Workstation Communication
SNow
Classification: ProtectState: Published
Disable all workstation to workstation communication to limit an attacker's ability to move laterally and compromise neighboring systems, through technologies such as Private VLANs or microsegmentation.
Document Traffic Configuration Rules
SNow
Classification: IdentifyState: Published
All configuration rules that allow traffic to flow through network devices should be documented in a configuration management system with a specific business reason for each rule, a specific individuals name responsible for that business need, and an expected duration of the need.
Enable DNS Query Logging
SNow
Classification: DetectState: Published
This is a great passive way to monitor for malware in an environment. these sensors can log all of these queries without having to pull them off of the endpoint. Looking for new DNS queries and those that look to be computer-generated will be quick wins in terms of hunting out malware infections.
Citations (1)
Parent
Enable Detailed Logging
SNow
Classification: DetectState: Published
Enable system logging to include detailed information such as a event source, date, user, timestamp, source addresses, destination addresses, and other useful elements.
Citations (1)
Enable Firewall Filtering Between VLANs
SNow
Classification: ProtectState: Published
Enable firewall filtering between VLANs to ensure that only authorized systems are able to communicate with other systems necessary to fulfill their specific responsibilities.
Ensure adequate storage for logs
SNow
Classification: DetectState: Published
Ensure that all systems that store logs have adequate storage space for the logs generated.
Implement DMARC and Enable Receiver-Side Verification
SNow
Classification: ProtectState: Published
To lower the chance of spoofed or modified emails from valid domains, implement Domain-based Message Authentication, Reporting and Conformance (DMARC) policy and verification, starting by implementing the Sender Policy Framework (SPF) and the DomainKeys Identified Mail(DKIM) standards.
Include Tests for Presence of Unprotected System Information and Artifacts
SNow
Classification: DetectState: Published
Include tests for the presence of unprotected system information and artifacts that would be useful to attackers, including network diagrams, configuration files, older penetration test reports, e-mails or documents containing passwords or other information critical to system operation.
Leverage the Advanced Encryption Standard (AES) to Encrypt Wireless Data
SNow
Classification: ProtectState: Published
Leverage the Advanced Encryption Standard (AES) to encrypt wireless data in transit.
Parent
Log all URL requests
SNow
Classification: DetectState: Published
Log all URL requests from each of the organization's systems, whether onsite or a mobile device, in order to identify potentially malicious activity and assist incident handlers with identifying potentially compromised systems.
Maintain Standard Security Configurations for Network Devices
SNow
Classification: IdentifyState: Published
Maintain standard, documented security configuration standards for all authorized network devices.
Maintain an Inventory of Authorized Wireless Access Points
SNow
Classification: IdentifyState: Published
Maintain an inventory of authorized wireless access points connected to the wired network.
Parent
Maintain an Inventory of Network Boundaries
SNow
Classification: IdentifyState: Published
Maintain an up-to-date inventory of all of the organization's network boundaries.
Parent
Maintain and Enforce Network-Based URL Filters
SNow
Classification: ProtectState: Published
Enforce network-based URL filters that limit a system's ability to connect to websites not approved by the organization. This filtering shall be enforced for each of the organization's systems, whether they are physically at an organization's facilities or not.
Maintenance, Monitoring and Analysis of Audit Logs
SNow
Classification: DetectState: Published
Collect, manage, and analyze audit logs of events that could help detect, understand, or recover from an attack.
Manage Network Devices Using Multi-Factor Authentication and Encrypted Sessions
SNow
Classification: ProtectState: Published
Manage all network devices using multi-factor authentication and encrypted sessions.
Manage Network Infrastructure Through a Dedicated Network
SNow
Classification: ProtectState: Published
Manage the network infrastructure across network connections that are separated from the business use of that network, relying on separate VLANs or, preferably, on entirely different physical connectivity for management sessions for network devices.
Regularly Review Logs
SNow
Classification: DetectState: Published
On a regular basis, review logs to identify anomalies or abnormal events.
Regularly Tune SIEM
SNow
Classification: DetectState: Published
On a regular basis, tune your SIEM system to better identify actionable events and decrease event noise.
Sandbox All Email Attachments
SNow
Classification: ProtectState: Published
Use sandboxing to analyze and block inbound email attachments with malicious behavior.
Scan for Unauthorized Connections across Trusted Network Boundaries
SNow
Classification: DetectState: Published
Perform regular scans from outside each trusted network boundary to detect any unauthorized connections which are accessible across the boundary.
Parent
Secure Configuration for Network Devices, such as Firewalls, Routers and Switches
SNow
Classification: IdentifyState: Published
Establish, implement, and actively manage (track, report on, correct) the security configuration of network infrastructure devices using a rigorous configuration management and change control process in order to prevent attackers from exploiting vulnerable services and settings.
Children (7)
- Document Traffic Configuration Rules
- Install the Latest Stable Version of Any Security-related Up...
- Maintain Standard Security Configurations for Network Device...
- Manage Network Devices Using Multi-Factor Authentication and...
- Manage Network Infrastructure Through a Dedicated Network
- Use Automated Tools to Verify Standard Device Configurations...
- Use Dedicated Machines For All Network Administrative Tasks
Segment the Network Based on Sensitivity
SNow
Classification: ProtectState: Published
Segment the network based on the label or classification level of the information stored on the servers, locate all sensitive information on separated Virtual Local Area Networks (VLANs).
Subscribe to URL-Categorization service
SNow
Classification: ProtectState: Published
Subscribe to URL categorization services to ensure that they are up-to-date with the most recent website category definitions available. Uncategorized sites shall be blocked by default.
The manufacturing system architecture should be in line with DIA OT CS Network Segmentation Concept.
SNow
Classification: ProtectState: Published
The manufacturing system architecture should be in line with DIA OT CS Network Segmentation Concept.
Use Automated Tools to Verify Standard Device Configurations and Detect Changes
SNow
Classification: DetectState: Published
Compare all network device configuration against approved security configurations defined for each network device in use and alert when any deviations are discovered.
Use Dedicated Machines For All Network Administrative Tasks
SNow
Classification: ProtectState: Published
Ensure network engineers use a dedicated machine for all administrative tasks or tasks requiring elevated access. This machine shall be segmented from the organization's primary network and not be allowed Internet access. This machine shall not be used for reading e-mail, composing documents, or sur
Use Wireless Authentication Protocols that Require Mutual, Multi-Factor Authentication
SNow
Classification: ProtectState: Published
Ensure that wireless networks use authentication protocols such as Extensible Authentication Protocol-Transport Layer Security (EAP/TLS), that requires mutual, multi-factor authentication.
Parent
Use a Wireless Intrusion Detection System
SNow
Classification: DetectState: Published
Use a wireless intrusion detection system (WIDS) to detect and alert on unauthorized wireless access points connected to the network.
Parent
Use of DNS Filtering Services
SNow
Classification: ProtectState: Published
Use DNS filtering services to help block access to known malicious domains.
Utilize Three Synchronized Time Sources
SNow
Classification: DetectState: Published
Use at least three synchronized time sources from which all servers and network devices retrieve time information on a regular basis so that timestamps in logs are consistent.
Wireless Access Control
SNow
Classification: IdentifyState: Published
The processes and tools used to track/control/prevent/correct the security use of wireless local area networks (WLANs), access points, and wireless client systems.
Children (10)
- Create Separate Wireless Network for Personal and Untrusted ...
- Detect Wireless Access Points Connected to the Wired Network
- Disable Peer-to-peer Wireless Network Capabilities on Wirele...
- Disable Wireless Access on Devices if Not Required
- Disable Wireless Peripheral Access of Devices
- Leverage the Advanced Encryption Standard (AES) to Encrypt W...
- Limit Wireless Access on Client Devices
- Maintain an Inventory of Authorized Wireless Access Points
- Use Wireless Authentication Protocols that Require Mutual, M...
- Use a Wireless Intrusion Detection System