CIS Controls CIS-4.4

Implement and manage a firewall on servers, where supported. Example implementations include a virtual firewall, operating system firewall, or a third-party firewall agent.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1021.002 SMB/Windows Admin Shares
Comments
Blocking inbound SMB (TCP 445/139) is a primary server firewall function and directly reduces lateral movement via administrative shares.
References
    CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1021.001 Remote Desktop Protocol
    Comments
    Restricting TCP 3389 to authorized management hosts directly limits unauthorized RDP access to servers.
    References
      CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1021 Remote Services
      Comments
      A default-deny host firewall directly restricts inbound remote service access to servers, reducing opportunities for remote administration and lateral movement.
      References
        CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1021.003 Distributed Component Object Model
        Comments
        DCOM relies on RPC communications that can be restricted through host firewall rules, limiting remote DCOM access to authorized systems. Dynamic RPC ports make the effectiveness dependent on careful firewall configuration.
        References
          CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1021.004 SSH
          Comments
          A default-deny server firewall can directly restrict inbound SSH, normally TCP 22, to approved management systems. This reduces unauthorized remote administration and lateral movement against Linux, macOS, and other SSH-enabled servers.
          References
            CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1021.005 VNC
            Comments
            A server firewall prevents unauthorized inbound VNC connections unless the relevant service and source systems are explicitly permitted.
            References
              CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1021.006 Windows Remote Management
              Comments
              Restricting WinRM ports, commonly TCP 5985 and 5986, to approved administrative systems directly limits unauthorized remote management of servers.
              References
                CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1048 Exfiltration Over Alternative Protocol
                Comments
                When outbound filtering is configured, a server firewall can block unauthorized protocols used to exfiltrate data. Effectiveness depends on whether egress rules are enforced rather than allowing unrestricted outbound traffic.
                References
                  CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol
                  Comments
                  Outbound firewall restrictions can block unapproved encrypted non-C2 protocols or destinations used for exfiltration. The control is less effective when the traffic uses an explicitly permitted protocol and destination.
                  References
                    CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
                    Comments
                    A managed egress policy can prevent servers from establishing unapproved asymmetric encrypted connections used to transfer data. This mitigation depends on restrictive outbound rules and destination controls.
                    References
                      CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
                      Comments
                      A host firewall can block unauthorized outbound protocols and ports used for unencrypted data exfiltration. Exfiltration over an explicitly permitted service may remain possible.
                      References
                        CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1071 Application Layer Protocol
                        Comments
                        Application-aware or restrictive outbound firewall rules can limit unauthorized HTTP, HTTPS, DNS, SMTP, and other application-layer communications used for command and control. A basic port-only policy provides limited protection when adversaries use permitted protocols.
                        References
                          CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1090 Proxy
                          Comments
                          Restricting outbound server connections can prevent malware from reaching unauthorized proxy infrastructure or accepting proxy traffic on unapproved ports. Proxy activity over approved channels may still succeed.
                          References
                            CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1095 Non-Application Layer Protocol
                            Comments
                            Host firewalls can restrict raw IP, ICMP, GRE, and other non-application-layer protocols used for command and control. The mitigation depends on denying protocols that the server does not explicitly require.
                            References
                              CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1105 Ingress Tool Transfer
                              Comments
                              Restrictive outbound firewall rules can prevent a compromised server from downloading tools or payloads from unapproved external systems. The mapping is partial because transfers over approved destinations and protocols may still be possible.
                              References
                                CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1133 External Remote Services
                                Comments
                                A default-deny host firewall reduces the exposure of externally accessible remote services by permitting only explicitly authorized ports, protocols, and source systems.
                                References
                                  CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1190 Exploit Public-Facing Application
                                  Comments
                                  A host firewall cannot remove vulnerabilities in a public-facing application, but it can ensure that only intended application ports are reachable and restrict access by source where operationally feasible. This reduces unnecessary exposure and possible exploitation paths.
                                  References
                                    CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1205.001 Port Knocking
                                    Comments
                                    Port knocking relies on specific traffic patterns that cause a firewall or related mechanism to expose a service port. Managed default-deny rules and monitoring of unauthorized firewall changes can restrict the trigger traffic and prevent unapproved ports from being opened.
                                    References
                                      CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1210 Exploitation of Remote Services
                                      Comments
                                      Exploitation of a remote service requires network reachability to the vulnerable service. A default-deny server firewall reduces the number of reachable services and limits access to authorized source systems.
                                      References
                                        CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1219 Remote Access Tools
                                        Comments
                                        Host firewall rules can block inbound or outbound communications associated with unauthorized remote access software. The firewall does not prevent the software from being installed or executed when it communicates over an allowed channel.
                                        References
                                          CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1537 Transfer Data to Cloud Account
                                          Comments
                                          Egress filtering can restrict server connections to unauthorized cloud services or accounts, making cloud-based data transfer more difficult. The mitigation depends on destination-aware outbound controls.
                                          References
                                            CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1557.001 Name Resolution Poisoning and SMB Relay
                                            Comments
                                            Blocking unnecessary LLMNR, NBT-NS, mDNS, NetBIOS, and SMB traffic can reduce name-resolution poisoning and relay opportunities involving servers. Disabling the protocols and enforcing SMB signing remain stronger primary mitigations.
                                            References
                                              CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1557.002 ARP Cache Poisoning
                                              Comments
                                              A host firewall may restrict follow-on connections created through ARP poisoning, but it has limited ability to prevent manipulation of Layer 2 address resolution itself. This is therefore a weak and environment-dependent mitigation.
                                              References
                                                CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1557.003 DHCP Spoofing
                                                Comments
                                                A host firewall may limit some follow-on communications after a malicious DHCP configuration is accepted, but it does not directly prevent DHCP spoofing. Network access controls and DHCP protections are the primary mitigations.
                                                References
                                                  CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1570 Lateral Tool Transfer
                                                  Comments
                                                  Lateral tool transfers often rely on SMB, WinRM, SSH, or other network services that are directly governed by server firewall rules. Restricting those services to approved systems impedes common transfer channels.
                                                  References
                                                    CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1571 Non-Standard Port
                                                    Comments
                                                    A default-deny firewall blocks communication over arbitrary or non-standard ports unless they are explicitly permitted, directly limiting adversary use of unexpected ports.
                                                    References
                                                      CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1572 Protocol Tunneling
                                                      Comments
                                                      Restricting permitted ports, protocols, and destinations can impede protocol tunneling from compromised servers. Tunnels carried inside an explicitly allowed protocol may still bypass simple port-based filtering.
                                                      References
                                                        CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1602.001 SNMP (MIB Dump)
                                                        Comments
                                                        Blocking unnecessary SNMP traffic and restricting authorized SNMP sources reduces the ability to query management information from servers or server-hosted management services. The applicability depends on whether the server exposes SNMP.
                                                        References
                                                          CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1686 Disable or Modify System Firewall
                                                          Comments
                                                          Adversaries may disable or alter host firewall configurations to expose services or enable unrestricted network communication, directly undermining the safeguard. Implementing and actively managing the firewall establishes the required configuration and supports identifying or correcting unauthorized changes.
                                                          References
                                                            CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1686.001 Cloud Firewall
                                                            Comments
                                                            This sub-technique concerns changes to cloud firewall rules or security groups rather than a host-based firewall installed on a server. The relationship to Safeguard 4.4 is therefore indirect and primarily relevant where server firewall management also encompasses associated cloud firewall controls.
                                                            References
                                                              CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1686.002 Network Device Firewall
                                                              Comments
                                                              This sub-technique targets firewalls implemented on network infrastructure rather than host-based firewalls on servers. Its relationship to Safeguard 4.4 is weak and applies only where the server firewall management process also governs supporting network firewall policy.
                                                              References
                                                                CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1686.003 Windows Host Firewall
                                                                Comments
                                                                This sub-technique explicitly covers disabling or modifying the Windows host firewall, including changing profiles or rules to expose services or permit command-and-control traffic. Implementing and managing the required firewall configuration helps identify, prevent, or reverse unauthorized changes.
                                                                References
                                                                  CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1041 Exfiltration Over C2 Channel
                                                                  Comments
                                                                  This technique may be mitigated depending on where ingress and egress is tightly controlled. For example, the use network signatures such as IP addresses or domain names to identify traffic for specific adversary malware can be used to mitigate activity at the network level.
                                                                  References
                                                                    CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1205.002 Socket Filters
                                                                    Comments
                                                                    ATT&CK mentions that the mitigation of some variants of this technique could be achieved through the use of stateful firewalls, depending upon how it is implemented.
                                                                    References
                                                                      CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1552.005 Cloud Instance Metadata API
                                                                      Comments
                                                                      ATT&CK mentions to limit access to the Instance Metadata API using a host-based firewall such as iptables. A properly configured Web Application Firewall (WAF) may help prevent external adversaries from exploiting Server-side Request Forgery (SSRF) attacks that allow access to the Cloud Instance Metadata API.
                                                                      References
                                                                        CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1218.012 Verclsid
                                                                        Comments
                                                                        Consider modifying host firewall rules to prevent egress traffic from verclsid.exe.
                                                                        References
                                                                          CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1090.003 Multi-hop Proxy
                                                                          Comments
                                                                          This technique may be lessened or mitigated though the use of firewall policy that constrains relay and redirect paths.
                                                                          References
                                                                            CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1197 BITS Jobs
                                                                            Comments
                                                                            Modify network and/or host firewall rules, as well as other network controls, to only allow legitimate BITS traffic.
                                                                            References
                                                                              CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1205 Traffic Signaling
                                                                              Comments
                                                                              ATT&CK mentions that the mitigation of some variants of this technique could be achieved through the use of stateful firewalls, depending upon how it is implemented.
                                                                              References
                                                                                CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1071.001 Web Protocols
                                                                                Comments
                                                                                Adversaries use web protocols to blend with normal traffic. A server firewall can partially restrict which destinations, ports, and web services a server may contact, though it will not stop all HTTP/S abuse.
                                                                                References
                                                                                  CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1563.002 RDP Hijacking
                                                                                  Comments
                                                                                  Adversaries leverage RDP if it is reachable. Firewall rules are among the most direct ways to prevent unauthorized RDP reachability to servers.
                                                                                  References