risk
Internet-exposed or misconfigured systems
Adversary gains access through the Internet to systems not authorized for Internet connectivity or that do not meet configuration requirements, and exploits attacks over unauthorized ports, protocols, and services.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- cyber_security
- domain
- Secure Configuration & Change Management
- Network & Communications Security
- Vulnerability & Patch Management
- taxonomy
- nist-800-30-threat-event
- inherent_rating
- high
Details
- risk_id
- config-internet-exposed-misconfig
- category
- cyber_security
- likelihood
- high
- impact
- high
- inherent_rating
- high
- treatment
- mitigate
- taxonomies
- nist-800-30-threat-event
Source
No record-specific source URL is provided.
Connections
- UC-CONFIG-01 — Harden systems to approved secure configuration baselines mitigates Internet-exposed or misconfigured systems
- strength
- primary
- rationale
- Secure baselines plus least functionality (disabling unnecessary ports/protocols/services) remove the misconfigurations and unauthorized services attackers exploit.
- UC-NET-01 — Segment networks and defend the external boundary mitigates Internet-exposed or misconfigured systems
- strength
- primary
- rationale
- Deny-by-default boundary mediation blocks unauthorized Internet exposure and traffic over unauthorized ports, protocols, and services.
- UC-VULN-01 — Scan for vulnerabilities and track advisories on a defined cadence mitigates Internet-exposed or misconfigured systems
- strength
- related
- rationale
- Authenticated scans detect exposed ports/services and misconfigured internet-facing systems, enabling correction.
- UC-LOG-08 — Secure and monitor networks and network services mitigates Internet-exposed or misconfigured systems
- strength
- primary
- rationale
- Hardening/controlling network devices and monitoring network services for conformance with documented security features directly reduces misconfigured and unauthorized-exposure conditions.
- UC-CONFIG-10 — Map where information resides and how data is processed mitigates Internet-exposed or misconfigured systems
- strength
- related
- rationale
- Mapping where information and processing components reside surfaces data on unauthorized or misconfigured systems for remediation; it enables but is not the hardening defense.
- UC-VULN-02 — Test security through independent penetration exercises mitigates Internet-exposed or misconfigured systems
- strength
- related
- rationale
- External-perspective testing directly probes and discovers internet-exposed and misconfigured systems.