unified
UC-NET-09 — Reduce attack surface through resilient architecture
Architect infrastructure to resist attack and localize failures: deploy minimal-functionality (thin) nodes where feasible, employ heterogeneity in key technologies to avoid common-mode compromise, and distribute processing and storage across multiple physical locations or components. Review these architecture decisions against current threats periodically.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Network & Communications Security
- type
- preventive
- category
- technical
Details
- unified_id
- UC-NET-09
- title
- Reduce attack surface through resilient architecture
- statement
- Architect infrastructure to resist attack and localize failures: deploy minimal-functionality (thin) nodes where feasible, employ heterogeneity in key technologies to avoid common-mode compromise, and distribute processing and storage across multiple physical locations or components. Review these architecture decisions against current threats periodically.
- domain
- Network & Communications Security
- control_type
- preventive
- control_category
- technical
- members
- framework
- nist-800-53
- control_id
- SC-25
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- SC-29
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- SC-36
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-NET-09 — Reduce attack surface through resilient architecture mitigates Single-site / single-region / single-supply concentration
- strength
- primary
- rationale
- Distributing processing and storage across multiple physical locations directly counters single-site/single-region concentration and single points of failure.
- UC-NET-09 — Reduce attack surface through resilient architecture mitigates Denial-of-service and system saturation
- strength
- related
- rationale
- Distributing processing/storage removes single choke points, reducing the impact of a denial-of-service attack on any one node.
- UC-NET-09 — Reduce attack surface through resilient architecture maps_to SC-29 — Heterogeneity
- framework
- nist-800-53
- control_id
- SC-29
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-NET-09 — Reduce attack surface through resilient architecture maps_to SC-36 — Distributed Processing and Storage
- framework
- nist-800-53
- control_id
- SC-36
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Resilient Architecture & Non-Persistence Operations operates UC-NET-09 — Reduce attack surface through resilient architecture
- UC-NET-09 — Reduce attack surface through resilient architecture maps_to SC-25 — Thin Nodes
- framework
- nist-800-53
- control_id
- SC-25
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-NET-09 — Reduce attack surface through resilient architecture mitigates Poor network architecture and unprotected public connections
- strength
- related
- rationale
- Thin nodes, heterogeneity, and distribution add defense-in-depth and remove single points of failure in the architecture.
- Security Control Assessment & POA&M Remediation tests UC-NET-09 — Reduce attack surface through resilient architecture