Design and maintain a secure network architecture. A secure network architecture must address segmentation, least privilege, and availability, at a minimum. Example implementations may include documentation, policy, and design components.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1599.001 | Network Address Translation Traversal |
Comments
This sub-technique concerns traversing or bypassing network boundaries implemented through NAT and perimeter devices. Secure architecture using explicit trust zones, controlled routing, segmentation, and restricted inbound/outbound paths directly constrains the network reachability needed for NAT traversal.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1599 | Network Boundary Bridging |
Comments
This technique directly concerns adversaries compromising network devices to bypass segmentation and route prohibited traffic across trust boundaries. Because this control requires network segmentation and least privilege, designing and maintaining strong trust boundaries directly constrains the traffic paths the adversary is attempting to bridge. ATT&CK describes the technique specifically in terms of bypassing segmentation and boundary-device policy
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1557 | Adversary-in-the-Middle |
Comments
ATT&CK recommends network segmentation, traffic filtering, restricted access to network infrastructure, encryption, and network intrusion prevention for AiTM activity. Segmentation under this control reduces the network scope in which an adversary can position itself between communicating systems and restricts access to infrastructure capable of reshaping traffic
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1556.004 | Network Device Authentication |
Comments
This sub-technique specifically targets authentication on network devices. ATT&CK recommends MFA, privileged-account restriction, TACACS+/RADIUS, and vendor hardening; a secure network architecture that isolates the management plane and applies least-privilege administrative access directly constrains the access needed to modify network-device authentication.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1542.005 | TFTP Boot |
Comments
Adversaries can manipulate network-device boot configuration to load an unauthorized image from a malicious TFTP server. ATT&CK recommends limiting access to administrative interfaces, restricting insecure protocols, AAA/command authorization, and network-level filtering which are mechanisms that can be implemented as part of a secure management-plane architecture under this control.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1200 | Hardware Additions |
Comments
Adversaries may introduce unauthorized devices onto the network. ATT&CK recommends network access controls such as 802.1X, device certificates, and restricting DHCP to registered devices; these are architectural admission-control mechanisms that directly prevent unauthorized hardware from communicating with trusted systems.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1059.008 | Network Device CLI |
Comments
Adversaries use network-device CLIs to execute commands and modify device behavior. ATT&CK recommends AAA, least privilege, and command authorization such as TACACS+ to restrict which administrative commands users may execute. Because this control explicitly requires least privilege within the network architecture, this is a strong mapping when that architecture includes management-plane and command-access controls.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1021.002 | SMB/Windows Admin Shares |
Comments
Adversaries use SMB and administrative shares for remote access and lateral movement. A secure network architecture that enforces segmentation and least-privilege network access can restrict SMB connectivity to approved source/destination relationships, directly reducing the network reachability required for unauthorized lateral movement.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1669 | Wi-Fi Networks |
Comments
Adversaries obtain initial access by connecting to an organization's wireless network. Separating wireless access networks from sensitive enterprise segments with enforced routing and firewall controls directly limits what an attacker can reach after establishing wireless connectivity.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1199 | Trusted Relationship |
Comments
Adversaries abuse connectivity granted to trusted third parties or external organizations to reach enterprise resources. Segmented third-party access restricts those connections to explicitly authorized services and network zones, directly preventing movement beyond the intended trust boundary.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1072 | Software Deployment Tools |
Comments
Adversaries abuse centralized deployment or management systems to execute software or move laterally. Placing those systems in a restricted management segment and allowing access only from approved administrative hosts directly limits unauthorized interaction with the deployment infrastructure.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1048.003 | Exfiltration Over Unencrypted Non-C2 Protocol |
Comments
Adversaries use unencrypted alternate protocols to transfer stolen data. Inter-zone and egress filtering blocks unauthorized protocols and destinations, directly disrupting the exfiltration channel.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1048.002 | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
Comments
Adversaries use asymmetrically encrypted non-C2 protocols to move data outside the environment. Network controls restrict permitted protocols and destinations, directly blocking unauthorized encrypted exfiltration channels.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1048.001 | Exfiltration Over Symmetric Encrypted Non-C2 Protocol |
Comments
Adversaries exfiltrate data through encrypted non-C2 protocols that use symmetric encryption. Enforced protocol and destination allowlists deny unauthorized encrypted outbound channels, directly preventing the required network transfer.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1048 | Exfiltration Over Alternative Protocol |
Comments
Adversaries exfiltrate data using protocols other than their primary command-and-control channel. Protocol-aware egress and inter-zone controls restrict communications to approved protocols and destinations, directly blocking unauthorized alternate-protocol exfiltration paths.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1571 | Non-Standard Port |
Comments
Adversaries communicate over unusual ports to evade expected network controls. Explicit port allowlists and default-deny inter-zone filtering block unapproved ports, directly preventing those communications from traversing protected network boundaries.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1095 | Non-Application Layer Protocol |
Comments
Adversaries use lower-layer protocols for command-and-control or data transfer. Deny-by-default inter-segment filtering permits only explicitly authorized protocols, directly blocking unauthorized non-application-layer communications across security boundaries.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1021.006 | Windows Remote Management |
Comments
Adversaries use WinRM to execute commands remotely and move laterally. Segmentation restricts WinRM connectivity to designated administrative zones and systems, directly preventing unauthorized remote WinRM sessions.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1021.003 | Distributed Component Object Model |
Comments
Adversaries use DCOM to remotely execute actions on accessible Windows systems. Network segmentation blocks DCOM traffic outside explicitly authorized relationships, directly restricting the network connectivity required for remote DCOM execution.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1021.001 | Remote Desktop Protocol |
Comments
Adversaries use RDP for remote access and lateral movement between systems. Segmentation and inter-zone ACLs permit RDP only across approved administrative paths, directly preventing unauthorized RDP connectivity between network zones.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1602.002 | Network Device Configuration Dump |
Comments
Adversaries retrieve network-device configurations to obtain topology, credentials, routing information, or security policy. Isolating management interfaces and permitting access only from approved administrative systems directly prevents unauthorized systems from reaching the configuration interface.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1602.001 | SNMP (MIB Dump) |
Comments
Adversaries query SNMP to obtain device, interface, routing, and network information. Restricting SNMP to an isolated management plane with ACLs permitting only authorized management systems directly prevents unauthorized hosts from issuing MIB queries.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1133 | External Remote Services |
Comments
Adversaries use externally accessible VPNs, gateways, and remote-access services to enter enterprise networks. The architecture forces external access through designated controlled gateways while denying direct connectivity to internal resources, directly restricting unauthorized remote entry paths.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1557.001 | Name Resolution Poisoning and SMB Relay |
Comments
Adversaries poison local name-resolution traffic and relay authentication attempts to reachable services. Layer-2/Layer-3 segmentation and SMB access restrictions constrain the poisoning domain and relay destinations, directly reducing viable poisoning and relay paths.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1040 | Network Sniffing |
Comments
Adversaries capture traffic visible from their network position to obtain credentials, sessions, or operational information. Segmentation reduces the broadcast domains, traffic flows, and network segments visible from a compromised system, directly limiting the traffic available for passive collection.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1046 | Network Service Discovery |
Comments
Adversaries probe remote systems to identify accessible hosts, ports, and services. Enforced segmentation limits probe reachability across security boundaries, directly reducing the systems and services that can be discovered.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1210 | Exploitation of Remote Services |
Comments
Adversaries must reach a vulnerable remote service before exploiting it for lateral movement or execution. Network segmentation and least-privilege ACLs restrict which systems can communicate with those services, directly reducing exploitable network paths.
References
|