risk
Poor network architecture and unprotected public connections
Because externally-facing connections lack perimeter controls (firewalls, DMZ) and the network lacks segmentation, redundancy, and defense-in-depth, attackers can breach the boundary and move laterally and single points of failure go unmitigated, resulting in intrusion, data exfiltration, and outage.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- cyber_security
- domain
- Network & Communications Security
- Secure Configuration & Change Management
- taxonomy
- iso-27005-vulnerability
- inherent_rating
- high
Details
- risk_id
- net-poor-perimeter-architecture
- category
- cyber_security
- likelihood
- high
- impact
- high
- inherent_rating
- high
- treatment
- mitigate
- taxonomies
- iso-27005-vulnerability
Source
No record-specific source URL is provided.
Connections
- UC-CONFIG-01 — Harden systems to approved secure configuration baselines mitigates Poor network architecture and unprotected public connections
- strength
- related
- rationale
- Hardening network security controls (e.g., firewall baselines) contributes to boundary protection, but segmentation/DMZ architecture is the operative defense.
- UC-LOG-08 — Secure and monitor networks and network services mitigates Poor network architecture and unprotected public connections
- strength
- related
- rationale
- Actively securing networks and hardening network devices strengthens the perimeter, though segmentation/firewalls (UC-NET-01) are the operative boundary defense.
- UC-NET-01 — Segment networks and defend the external boundary mitigates Poor network architecture and unprotected public connections
- strength
- primary
- rationale
- Zone segmentation plus deny-by-default mediation at firewalls/gateways/proxies is the operative defense against unprotected public connections and lateral movement.
- UC-NET-09 — Reduce attack surface through resilient architecture mitigates Poor network architecture and unprotected public connections
- strength
- related
- rationale
- Thin nodes, heterogeneity, and distribution add defense-in-depth and remove single points of failure in the architecture.
- UC-NET-08 — Maintain communications availability under attack and failure mitigates Poor network architecture and unprotected public connections
- strength
- related
- rationale
- Alternate paths and graceful failure mitigate the redundancy and single-point-of-failure gaps in weak network architecture.