unified
UC-NET-01 — Segment networks and defend the external boundary
Segment networks into zones based on trust level, sensitivity, and function, and mediate all traffic at managed interfaces (firewalls, gateways, proxies) with deny-by-default rules at the external boundary and key internal boundaries. Monitor and control communications crossing each boundary to protect against threats originating outside the system boundary, and review segmentation and rule sets periodically.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Network & Communications Security
- type
- preventive
- category
- technical
Details
- unified_id
- UC-NET-01
- title
- Segment networks and defend the external boundary
- statement
- Segment networks into zones based on trust level, sensitivity, and function, and mediate all traffic at managed interfaces (firewalls, gateways, proxies) with deny-by-default rules at the external boundary and key internal boundaries. Monitor and control communications crossing each boundary to protect against threats originating outside the system boundary, and review segmentation and rule sets periodically.
- domain
- Network & Communications Security
- control_type
- preventive
- control_category
- technical
- members
- framework
- nist-800-53
- control_id
- SC-7
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- PR.IR-01
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.8.22
- coverage
- full
- relationship
- superset_of
- framework
- soc2
- control_id
- CC6.6
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-NET-01 — Segment networks and defend the external boundary
- UC-NET-01 — Segment networks and defend the external boundary maps_to PR.IR-01 — Technology Infrastructure Resilience: Networks and environments are protected from unauthorized logical access and usage
- framework
- nist-csf-2
- control_id
- PR.IR-01
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-NET-01 — Segment networks and defend the external boundary mitigates Internet-exposed or misconfigured systems
- strength
- primary
- rationale
- Deny-by-default boundary mediation blocks unauthorized Internet exposure and traffic over unauthorized ports, protocols, and services.
- UC-NET-01 — Segment networks and defend the external boundary mitigates Session hijacking and unauthorized-protocol egress
- strength
- primary
- rationale
- Deny-by-default egress control and monitoring of communications crossing the boundary block exfiltration over unauthorized ports/protocols named in the risk.
- Technical Security Testing & Pentest Engagement tests UC-NET-01 — Segment networks and defend the external boundary
- UC-NET-01 — Segment networks and defend the external boundary mitigates Remote-work, mobile and split-tunneling exposure
- strength
- primary
- rationale
- Mediating and monitoring all traffic at managed boundaries restricts unauthorized logical access reaching in from remote/mobile networks (mustKeep).
- UC-NET-01 — Segment networks and defend the external boundary mitigates Adversary reconnaissance and information gathering
- strength
- related
- rationale
- Deny-by-default boundary reduces externally reachable/scannable services, shrinking the attack surface adversaries map.
- SOC 2 Trust Services Readiness tests UC-NET-01 — Segment networks and defend the external boundary
- UC-NET-01 — Segment networks and defend the external boundary mitigates Coordinated multi-stage / APT campaigns
- strength
- related
- rationale
- Internal segmentation with deny-by-default limits an intruder's lateral hopping between systems, containing campaign spread.
- Network Segmentation & Boundary Rule Management operates UC-NET-01 — Segment networks and defend the external boundary
- UC-NET-01 — Segment networks and defend the external boundary maps_to SC-7 — Boundary Protection
- framework
- nist-800-53
- control_id
- SC-7
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-NET-01 — Segment networks and defend the external boundary maps_to CC6.6 — The entity implements logical access security measures to protect against threats from sources outside its system boundaries.
- framework
- soc2
- control_id
- CC6.6
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-NET-01 — Segment networks and defend the external boundary mitigates Poor network architecture and unprotected public connections
- strength
- primary
- rationale
- Zone segmentation plus deny-by-default mediation at firewalls/gateways/proxies is the operative defense against unprotected public connections and lateral movement.
- UC-NET-01 — Segment networks and defend the external boundary maps_to A.8.22 — Segregation of networks
- framework
- iso-27001
- control_id
- A.8.22
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Security Control Assessment & POA&M Remediation tests UC-NET-01 — Segment networks and defend the external boundary