{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Network & Communications Security","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-NET-01","description":"Segment networks into zones based on trust level, sensitivity, and function, and mediate all traffic at managed interfaces (firewalls, gateways, proxies) with deny-by-default rules at the external boundary and key internal boundaries. Monitor and control communications crossing each boundary to protect against threats originating outside the system boundary, and review segmentation and rule sets periodically.","details":{"control_category":"technical","control_type":"preventive","domain":"Network & Communications Security","guidance":[],"members":[{"control_id":"SC-7","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PR.IR-01","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"A.8.22","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"CC6.6","coverage":"full","framework":"soc2","relationship":"superset_of"}],"statement":"Segment networks into zones based on trust level, sensitivity, and function, and mediate all traffic at managed interfaces (firewalls, gateways, proxies) with deny-by-default rules at the external boundary and key internal boundaries. Monitor and control communications crossing each boundary to protect against threats originating outside the system boundary, and review segmentation and rule sets periodically.","title":"Segment networks and defend the external boundary","unified_id":"UC-NET-01"},"id":"uc:UC-NET-01","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-NET-01","sourceIds":["iso-27001","nist-800-53","nist-csf-2","soc2"],"sourceUrl":null,"title":"UC-NET-01 — Segment networks and defend the external boundary","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0bf12f85a54f474ad5348f1e3e2723eadf5623f126b70320674f8967e488f864","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-net-01-30bfdc5f.json","targetId":"uc:UC-NET-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:134a498360c0422e5927d2900b8f3f44630ba1bfe2a725b3941c3de58cc70001","properties":{"control_id":"PR.IR-01","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-net-01-30bfdc5f.json","sourceId":"uc:UC-NET-01","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-pr-ir-01-9d7ae2fb.json","targetId":"ctrl:nist-csf-2:PR.IR-01","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2a369f94ea15f26df4ea6f1f5ccbea7fc6ddee0743b25dd6713baabcb3f9bae5","properties":{"rationale":"Deny-by-default boundary mediation blocks unauthorized Internet exposure and traffic over unauthorized ports, protocols, and services.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-net-01-30bfdc5f.json","sourceId":"uc:UC-NET-01","targetDetailPath":"/data/v1/records/risk-config-internet-exposed-misconfig-61b3613a.json","targetId":"risk:config-internet-exposed-misconfig","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:31b4f0d75b70d4f10a48567f6a5f4649166edb266cf0c28fd5e2e5f8d3d338b6","properties":{"rationale":"Deny-by-default egress control and monitoring of communications crossing the boundary block exfiltration over unauthorized ports/protocols named in the risk.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-net-01-30bfdc5f.json","sourceId":"uc:UC-NET-01","targetDetailPath":"/data/v1/records/risk-net-session-hijacking-434ddd0c.json","targetId":"risk:net-session-hijacking","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:36b34bdad817a44b1861e211a7e9586746683c2bae89309d2db34a7425bfd8b6","properties":{},"sourceDetailPath":"/data/v1/records/wf-c10-29ff1ddb.json","sourceId":"wf:C10","targetDetailPath":"/data/v1/records/uc-uc-net-01-30bfdc5f.json","targetId":"uc:UC-NET-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3cf14e2ddbee81a224b96621b7542a97b250df4088c9fd0d3ff357f3a789569b","properties":{"rationale":"Mediating and monitoring all traffic at managed boundaries restricts unauthorized logical access reaching in from remote/mobile networks (mustKeep).","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-net-01-30bfdc5f.json","sourceId":"uc:UC-NET-01","targetDetailPath":"/data/v1/records/risk-net-remote-work-mobile-exposure-d7aab6d9.json","targetId":"risk:net-remote-work-mobile-exposure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3e46286a36f9c16aae646c1f3d1213f70e9d73f89964fb92865df5fc91568bba","properties":{"rationale":"Deny-by-default boundary reduces externally reachable/scannable services, shrinking the attack surface adversaries map.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-net-01-30bfdc5f.json","sourceId":"uc:UC-NET-01","targetDetailPath":"/data/v1/records/risk-cyber-reconnaissance-3a7a6c33.json","targetId":"risk:cyber-reconnaissance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5370b42026d5fea9b4684a28bc88153eae5a9126865c11367a62439fea178956","properties":{},"sourceDetailPath":"/data/v1/records/wf-a15-e859f6b8.json","sourceId":"wf:A15","targetDetailPath":"/data/v1/records/uc-uc-net-01-30bfdc5f.json","targetId":"uc:UC-NET-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:55409d00ae2ca068bd2082a7df6baef0eb46372e4e19254a95e598cb654ab197","properties":{"rationale":"Internal segmentation with deny-by-default limits an intruder's lateral hopping between systems, containing campaign spread.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-net-01-30bfdc5f.json","sourceId":"uc:UC-NET-01","targetDetailPath":"/data/v1/records/risk-cyber-coordinated-campaign-b5879769.json","targetId":"risk:cyber-coordinated-campaign","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6fc5f80b1c6124c0e7289eb1f3533b6b9d8dbfcdb7f7008615e82cbafb5d2af8","properties":{},"sourceDetailPath":"/data/v1/records/wf-c48-1fcd5f42.json","sourceId":"wf:C48","targetDetailPath":"/data/v1/records/uc-uc-net-01-30bfdc5f.json","targetId":"uc:UC-NET-01","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8b7e9205c43ca892356f3952612097e09278f26f404e47217948e954a378b1c1","properties":{"control_id":"SC-7","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-01-30bfdc5f.json","sourceId":"uc:UC-NET-01","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-7-6ed77786.json","targetId":"ctrl:nist-800-53:SC-7","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b1c905c690707c5e5b1808360bd40c7cd93ac373d9eb4d23cabedda2c2e3fe3d","properties":{"control_id":"CC6.6","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-net-01-30bfdc5f.json","sourceId":"uc:UC-NET-01","targetDetailPath":"/data/v1/records/ctrl-soc2-cc6-6-31bdbb9f.json","targetId":"ctrl:soc2:CC6.6","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d0ef9dfb2ff2e380b22e063241000e2973923fb1b81bde6ad50a0a29bba8a376","properties":{"rationale":"Zone segmentation plus deny-by-default mediation at firewalls/gateways/proxies is the operative defense against unprotected public connections and lateral movement.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-net-01-30bfdc5f.json","sourceId":"uc:UC-NET-01","targetDetailPath":"/data/v1/records/risk-net-poor-perimeter-architecture-26b5f06f.json","targetId":"risk:net-poor-perimeter-architecture","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d76ebfe31f21c2186bd8d943cc9a6d3c0ec35cc97fd13308cabc92f979186c55","properties":{"control_id":"A.8.22","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-net-01-30bfdc5f.json","sourceId":"uc:UC-NET-01","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-22-be69b805.json","targetId":"ctrl:iso-27001:A.8.22","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f3c2262957b92c9003c8dc00fb4b884bef80e8bb52492e196ed7896ba84acd3d","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-net-01-30bfdc5f.json","targetId":"uc:UC-NET-01","type":"tests"}],"schemaVersion":1}
