unified

UC-NET-01 — Segment networks and defend the external boundary

Segment networks into zones based on trust level, sensitivity, and function, and mediate all traffic at managed interfaces (firewalls, gateways, proxies) with deny-by-default rules at the external boundary and key internal boundaries. Monitor and control communications crossing each boundary to protect against threats originating outside the system boundary, and review segmentation and rule sets periodically.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Network & Communications Security
type
preventive
category
technical

Details

unified_id
UC-NET-01
title
Segment networks and defend the external boundary
statement
Segment networks into zones based on trust level, sensitivity, and function, and mediate all traffic at managed interfaces (firewalls, gateways, proxies) with deny-by-default rules at the external boundary and key internal boundaries. Monitor and control communications crossing each boundary to protect against threats originating outside the system boundary, and review segmentation and rule sets periodically.
domain
Network & Communications Security
control_type
preventive
control_category
technical
members
  • framework
    nist-800-53
    control_id
    SC-7
    coverage
    full
    relationship
    superset_of
  • framework
    nist-csf-2
    control_id
    PR.IR-01
    coverage
    full
    relationship
    superset_of
  • framework
    iso-27001
    control_id
    A.8.22
    coverage
    full
    relationship
    superset_of
  • framework
    soc2
    control_id
    CC6.6
    coverage
    full
    relationship
    superset_of
guidance

    Source

    No record-specific source URL is provided.

    Connections