Ensure network infrastructure is kept up-to-date. Example implementations include running the latest stable release of software and/or using currently supported network as a service (NaaS) offerings. Review software versions monthly, or more frequently, to verify software support.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-12.1 | Ensure Network Infrastructure is Up-to-Date | mitigates | T1601.002 | Downgrade System Image |
Comments
Adversaries downgrade network-device software to reintroduce vulnerable or weaker code. Enforced anti-rollback and approved-version controls prevent installation of older unauthorized images, directly blocking the downgrade behavior.
References
|
| CIS-12.1 | Ensure Network Infrastructure is Up-to-Date | mitigates | T1686.002 | Network Device Firewall |
Comments
Adversaries may exploit vulnerable network firewalls to gain the privileged access required to alter ACLs, zones, or firewall policy. Maintaining supported and patched firewall software removes known vulnerability-based access paths, directly reducing the adversary's ability to reach the configuration state required to modify the firewall.
References
|
| CIS-12.1 | Ensure Network Infrastructure is Up-to-Date | mitigates | T1210 | Exploitation of Remote Services |
Comments
Adversaries exploit vulnerabilities in remotely reachable services to execute code or move laterally. Updating network-device software removes known vulnerabilities from those services, directly preventing exploitation paths that depend on obsolete or vulnerable software.
References
|
| CIS-12.1 | Ensure Network Infrastructure is Up-to-Date | mitigates | T1190 | Exploit Public-Facing Application |
Comments
Adversaries exploit vulnerabilities in Internet-facing services or network-device management interfaces to gain initial access. Keeping network infrastructure on supported, current software removes known exploitable vulnerabilities, directly reducing the adversary's ability to successfully exploit those exposed services.
References
|