CIS Controls CIS-12.2

Design and maintain a secure network architecture. A secure network architecture must address segmentation, least privilege, and availability, at a minimum. Example implementations may include documentation, policy, and design components.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1599.001 Network Address Translation Traversal
Comments
This sub-technique concerns traversing or bypassing network boundaries implemented through NAT and perimeter devices. Secure architecture using explicit trust zones, controlled routing, segmentation, and restricted inbound/outbound paths directly constrains the network reachability needed for NAT traversal.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1599 Network Boundary Bridging
Comments
This technique directly concerns adversaries compromising network devices to bypass segmentation and route prohibited traffic across trust boundaries. Because this control requires network segmentation and least privilege, designing and maintaining strong trust boundaries directly constrains the traffic paths the adversary is attempting to bridge. ATT&CK describes the technique specifically in terms of bypassing segmentation and boundary-device policy
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1557 Adversary-in-the-Middle
Comments
ATT&CK recommends network segmentation, traffic filtering, restricted access to network infrastructure, encryption, and network intrusion prevention for AiTM activity. Segmentation under this control reduces the network scope in which an adversary can position itself between communicating systems and restricts access to infrastructure capable of reshaping traffic
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1556.004 Network Device Authentication
Comments
This sub-technique specifically targets authentication on network devices. ATT&CK recommends MFA, privileged-account restriction, TACACS+/RADIUS, and vendor hardening; a secure network architecture that isolates the management plane and applies least-privilege administrative access directly constrains the access needed to modify network-device authentication.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1542.005 TFTP Boot
Comments
Adversaries can manipulate network-device boot configuration to load an unauthorized image from a malicious TFTP server. ATT&CK recommends limiting access to administrative interfaces, restricting insecure protocols, AAA/command authorization, and network-level filtering which are mechanisms that can be implemented as part of a secure management-plane architecture under this control.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1200 Hardware Additions
Comments
Adversaries may introduce unauthorized devices onto the network. ATT&CK recommends network access controls such as 802.1X, device certificates, and restricting DHCP to registered devices; these are architectural admission-control mechanisms that directly prevent unauthorized hardware from communicating with trusted systems.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1059.008 Network Device CLI
Comments
Adversaries use network-device CLIs to execute commands and modify device behavior. ATT&CK recommends AAA, least privilege, and command authorization such as TACACS+ to restrict which administrative commands users may execute. Because this control explicitly requires least privilege within the network architecture, this is a strong mapping when that architecture includes management-plane and command-access controls.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1021.002 SMB/Windows Admin Shares
Comments
Adversaries use SMB and administrative shares for remote access and lateral movement. A secure network architecture that enforces segmentation and least-privilege network access can restrict SMB connectivity to approved source/destination relationships, directly reducing the network reachability required for unauthorized lateral movement.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1669 Wi-Fi Networks
Comments
Adversaries obtain initial access by connecting to an organization's wireless network. Separating wireless access networks from sensitive enterprise segments with enforced routing and firewall controls directly limits what an attacker can reach after establishing wireless connectivity.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1199 Trusted Relationship
Comments
Adversaries abuse connectivity granted to trusted third parties or external organizations to reach enterprise resources. Segmented third-party access restricts those connections to explicitly authorized services and network zones, directly preventing movement beyond the intended trust boundary.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1072 Software Deployment Tools
Comments
Adversaries abuse centralized deployment or management systems to execute software or move laterally. Placing those systems in a restricted management segment and allowing access only from approved administrative hosts directly limits unauthorized interaction with the deployment infrastructure.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
Comments
Adversaries use unencrypted alternate protocols to transfer stolen data. Inter-zone and egress filtering blocks unauthorized protocols and destinations, directly disrupting the exfiltration channel.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
Comments
Adversaries use asymmetrically encrypted non-C2 protocols to move data outside the environment. Network controls restrict permitted protocols and destinations, directly blocking unauthorized encrypted exfiltration channels.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol
Comments
Adversaries exfiltrate data through encrypted non-C2 protocols that use symmetric encryption. Enforced protocol and destination allowlists deny unauthorized encrypted outbound channels, directly preventing the required network transfer.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1048 Exfiltration Over Alternative Protocol
Comments
Adversaries exfiltrate data using protocols other than their primary command-and-control channel. Protocol-aware egress and inter-zone controls restrict communications to approved protocols and destinations, directly blocking unauthorized alternate-protocol exfiltration paths.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1571 Non-Standard Port
Comments
Adversaries communicate over unusual ports to evade expected network controls. Explicit port allowlists and default-deny inter-zone filtering block unapproved ports, directly preventing those communications from traversing protected network boundaries.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1095 Non-Application Layer Protocol
Comments
Adversaries use lower-layer protocols for command-and-control or data transfer. Deny-by-default inter-segment filtering permits only explicitly authorized protocols, directly blocking unauthorized non-application-layer communications across security boundaries.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1021.006 Windows Remote Management
Comments
Adversaries use WinRM to execute commands remotely and move laterally. Segmentation restricts WinRM connectivity to designated administrative zones and systems, directly preventing unauthorized remote WinRM sessions.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1021.003 Distributed Component Object Model
Comments
Adversaries use DCOM to remotely execute actions on accessible Windows systems. Network segmentation blocks DCOM traffic outside explicitly authorized relationships, directly restricting the network connectivity required for remote DCOM execution.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1021.001 Remote Desktop Protocol
Comments
Adversaries use RDP for remote access and lateral movement between systems. Segmentation and inter-zone ACLs permit RDP only across approved administrative paths, directly preventing unauthorized RDP connectivity between network zones.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1602.002 Network Device Configuration Dump
Comments
Adversaries retrieve network-device configurations to obtain topology, credentials, routing information, or security policy. Isolating management interfaces and permitting access only from approved administrative systems directly prevents unauthorized systems from reaching the configuration interface.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1602.001 SNMP (MIB Dump)
Comments
Adversaries query SNMP to obtain device, interface, routing, and network information. Restricting SNMP to an isolated management plane with ACLs permitting only authorized management systems directly prevents unauthorized hosts from issuing MIB queries.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1133 External Remote Services
Comments
Adversaries use externally accessible VPNs, gateways, and remote-access services to enter enterprise networks. The architecture forces external access through designated controlled gateways while denying direct connectivity to internal resources, directly restricting unauthorized remote entry paths.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1557.001 Name Resolution Poisoning and SMB Relay
Comments
Adversaries poison local name-resolution traffic and relay authentication attempts to reachable services. Layer-2/Layer-3 segmentation and SMB access restrictions constrain the poisoning domain and relay destinations, directly reducing viable poisoning and relay paths.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1040 Network Sniffing
Comments
Adversaries capture traffic visible from their network position to obtain credentials, sessions, or operational information. Segmentation reduces the broadcast domains, traffic flows, and network segments visible from a compromised system, directly limiting the traffic available for passive collection.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1046 Network Service Discovery
Comments
Adversaries probe remote systems to identify accessible hosts, ports, and services. Enforced segmentation limits probe reachability across security boundaries, directly reducing the systems and services that can be discovered.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1210 Exploitation of Remote Services
Comments
Adversaries must reach a vulnerable remote service before exploiting it for lateral movement or execution. Network segmentation and least-privilege ACLs restrict which systems can communicate with those services, directly reducing exploitable network paths.
References