CIS Controls CIS-12.6

Adopt secure network management protocols (e.g., 802.1X) and secure communication protocols (e.g., Wi-Fi Protected Access 2 (WPA2) Enterprise or more secure alternatives).

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-12.6 Use of Secure Network Management and Communication Protocols mitigates T1542.005 TFTP Boot
Comments
Adversaries can abuse unauthenticated network-boot mechanisms to load malicious or unauthorized system images. Disabling insecure TFTP/PXE boot or restricting it to authenticated management infrastructure directly prevents unauthorized network boot operations.
References
CIS-12.6 Use of Secure Network Management and Communication Protocols mitigates T1602.001 SNMP (MIB Dump)
Comments
Adversaries can query SNMP to collect network-device and topology information. Enforced SNMPv3 authentication, encryption, and management-source restrictions directly prevent unauthorized systems from successfully issuing or reading management queries.
References
CIS-12.6 Use of Secure Network Management and Communication Protocols mitigates T1557.004 Evil Twin
Comments
Adversaries can deploy a rogue access point impersonating the legitimate enterprise WLAN to capture credentials or intercept communications. Managed 802.1X supplicants validate the trusted RADIUS/EAP server certificate and approved wireless profile, directly preventing endpoints from authenticating to the rogue infrastructure.
References
CIS-12.6 Use of Secure Network Management and Communication Protocols mitigates T1557 Adversary-in-the-Middle
Comments
Adversaries can intercept or manipulate communications between wireless clients and enterprise infrastructure. Enterprise authentication and encrypted wireless communications provide confidentiality and integrity protections that directly constrain interception and modification.
References
CIS-12.6 Use of Secure Network Management and Communication Protocols mitigates T1040 Network Sniffing
Comments
Adversaries can capture wireless network traffic to recover credentials or sensitive information. WPA2 Enterprise or stronger encryption protects wireless frames from passive observers, directly preventing useful plaintext recovery from captured traffic.
References
CIS-12.6 Use of Secure Network Management and Communication Protocols mitigates T1669 Wi-Fi Networks
Comments
Adversaries can gain initial access by associating with the target organization's wireless network. Secure network management protocols like 802.1X and enterprise wireless authentication require authorized credentials or device identity before admission, directly preventing unauthorized wireless access.
References
CIS-12.6 Use of Secure Network Management and Communication Protocols mitigates T1200 Hardware Additions
Comments
Adversaries can attach rogue computers, appliances, or networking hardware to obtain enterprise network connectivity. Secure network management protocols like 802.1X requires successful user or device authentication before network admission, directly denying unauthorized hardware access.
References