CIS Controls CIS-12.3

Securely manage network infrastructure. Example implementations include version-controlled Infrastructure-as-Code (IaC), and the use of secure network protocols, such as SSH and HTTPS.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-12.3 Securely Manage Network Infrastructure mitigates T1686.002 Network Device Firewall
Comments
Adversaries can alter ACLs, firewall rules, or network security zones to create unauthorized access paths. Enforced IaC/GitOps configuration management validates approved firewall state and rejects or automatically reverses unauthorized policy changes, directly disrupting the modification.
References
CIS-12.3 Securely Manage Network Infrastructure mitigates T1059.008 Network Device CLI
Comments
Adversaries can use network-device command-line interfaces to make malicious configuration changes. Enforced version-controlled Infrastructure-as-Code with direct configuration disabled or automatically reconciled prevents unauthorized CLI changes from becoming persistent device state.
References
CIS-12.3 Securely Manage Network Infrastructure mitigates T1659 Content Injection
Comments
Adversaries can inject malicious content into network communications while positioned along the traffic path. Integrity-protected SSH or HTTPS management sessions reject unauthorized modifications, directly preventing injected content from becoming part of the protected administrative session.
References
CIS-12.3 Securely Manage Network Infrastructure mitigates T1557 Adversary-in-the-Middle
Comments
Adversaries can position themselves between communicating systems to intercept or alter network traffic. Authenticated and encrypted management sessions provide confidentiality, peer authentication, and integrity protection, directly preventing useful interception or modification of administrative communications.
References
CIS-12.3 Securely Manage Network Infrastructure mitigates T1040 Network Sniffing
Comments
Adversaries can passively capture management traffic to obtain credentials, commands, or configuration information. SSH, HTTPS, and equivalent encrypted management protocols make captured administrative traffic unreadable, directly reducing the value of network sniffing.
References