Adopt secure network management protocols (e.g., 802.1X) and secure communication protocols (e.g., Wi-Fi Protected Access 2 (WPA2) Enterprise or more secure alternatives).
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-12.6 | Use of Secure Network Management and Communication Protocols | mitigates | T1542.005 | TFTP Boot |
Comments
Adversaries can abuse unauthenticated network-boot mechanisms to load malicious or unauthorized system images. Disabling insecure TFTP/PXE boot or restricting it to authenticated management infrastructure directly prevents unauthorized network boot operations.
References
|
| CIS-12.6 | Use of Secure Network Management and Communication Protocols | mitigates | T1602.001 | SNMP (MIB Dump) |
Comments
Adversaries can query SNMP to collect network-device and topology information. Enforced SNMPv3 authentication, encryption, and management-source restrictions directly prevent unauthorized systems from successfully issuing or reading management queries.
References
|
| CIS-12.6 | Use of Secure Network Management and Communication Protocols | mitigates | T1557.004 | Evil Twin |
Comments
Adversaries can deploy a rogue access point impersonating the legitimate enterprise WLAN to capture credentials or intercept communications. Managed 802.1X supplicants validate the trusted RADIUS/EAP server certificate and approved wireless profile, directly preventing endpoints from authenticating to the rogue infrastructure.
References
|
| CIS-12.6 | Use of Secure Network Management and Communication Protocols | mitigates | T1557 | Adversary-in-the-Middle |
Comments
Adversaries can intercept or manipulate communications between wireless clients and enterprise infrastructure. Enterprise authentication and encrypted wireless communications provide confidentiality and integrity protections that directly constrain interception and modification.
References
|
| CIS-12.6 | Use of Secure Network Management and Communication Protocols | mitigates | T1040 | Network Sniffing |
Comments
Adversaries can capture wireless network traffic to recover credentials or sensitive information. WPA2 Enterprise or stronger encryption protects wireless frames from passive observers, directly preventing useful plaintext recovery from captured traffic.
References
|
| CIS-12.6 | Use of Secure Network Management and Communication Protocols | mitigates | T1669 | Wi-Fi Networks |
Comments
Adversaries can gain initial access by associating with the target organization's wireless network. Secure network management protocols like 802.1X and enterprise wireless authentication require authorized credentials or device identity before admission, directly preventing unauthorized wireless access.
References
|
| CIS-12.6 | Use of Secure Network Management and Communication Protocols | mitigates | T1200 | Hardware Additions |
Comments
Adversaries can attach rogue computers, appliances, or networking hardware to obtain enterprise network connectivity. Secure network management protocols like 802.1X requires successful user or device authentication before network admission, directly denying unauthorized hardware access.
References
|