{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Network & Communications Security","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-NET-09","description":"Architect infrastructure to resist attack and localize failures: deploy minimal-functionality (thin) nodes where feasible, employ heterogeneity in key technologies to avoid common-mode compromise, and distribute processing and storage across multiple physical locations or components. Review these architecture decisions against current threats periodically.","details":{"control_category":"technical","control_type":"preventive","domain":"Network & Communications Security","guidance":[],"members":[{"control_id":"SC-25","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SC-29","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SC-36","coverage":"full","framework":"nist-800-53","relationship":"superset_of"}],"statement":"Architect infrastructure to resist attack and localize failures: deploy minimal-functionality (thin) nodes where feasible, employ heterogeneity in key technologies to avoid common-mode compromise, and distribute processing and storage across multiple physical locations or components. Review these architecture decisions against current threats periodically.","title":"Reduce attack surface through resilient architecture","unified_id":"UC-NET-09"},"id":"uc:UC-NET-09","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-NET-09","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"UC-NET-09 — Reduce attack surface through resilient architecture","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1a9a1c7526a4b3c26fc4757de17cd2e5df23cb98741724d1e60073d1b36571a1","properties":{"rationale":"Distributing processing and storage across multiple physical locations directly counters single-site/single-region concentration and single points of failure.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-net-09-6777e6ac.json","sourceId":"uc:UC-NET-09","targetDetailPath":"/data/v1/records/risk-bcdr-single-point-concentration-91008453.json","targetId":"risk:bcdr-single-point-concentration","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2016d9d0b97b703894782f376e98d4c833a6f1c27c1ca110289146b06ec98c01","properties":{"rationale":"Distributing processing/storage removes single choke points, reducing the impact of a denial-of-service attack on any one node.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-net-09-6777e6ac.json","sourceId":"uc:UC-NET-09","targetDetailPath":"/data/v1/records/risk-net-denial-of-service-934ccd7f.json","targetId":"risk:net-denial-of-service","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:48f339bec31302dbafb9a26d791e6a61d8c90c866772a71e4d2850a0fbd97a2b","properties":{"control_id":"SC-29","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-09-6777e6ac.json","sourceId":"uc:UC-NET-09","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-29-664c0e90.json","targetId":"ctrl:nist-800-53:SC-29","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5fc8a8249cef0dfd69344b896f38c479c39c305a10a7cb1d73ff7ef359df584c","properties":{"control_id":"SC-36","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-09-6777e6ac.json","sourceId":"uc:UC-NET-09","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-36-c18e2da0.json","targetId":"ctrl:nist-800-53:SC-36","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a33ad770e68c9a433896453dc35ac35f40a6b88da303a262cd7d4c65fbef9920","properties":{},"sourceDetailPath":"/data/v1/records/wf-c51-460f7a67.json","sourceId":"wf:C51","targetDetailPath":"/data/v1/records/uc-uc-net-09-6777e6ac.json","targetId":"uc:UC-NET-09","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ac2d254daad4ebc8bbeebf39a11c2a509e4a1f28291693e461d051912d288b8f","properties":{"control_id":"SC-25","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-09-6777e6ac.json","sourceId":"uc:UC-NET-09","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-25-f331d135.json","targetId":"ctrl:nist-800-53:SC-25","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e1f3ec7c6dc144c46f9a47bc0593b64f49b204c13db538fd8ab4cdb222c57262","properties":{"rationale":"Thin nodes, heterogeneity, and distribution add defense-in-depth and remove single points of failure in the architecture.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-net-09-6777e6ac.json","sourceId":"uc:UC-NET-09","targetDetailPath":"/data/v1/records/risk-net-poor-perimeter-architecture-26b5f06f.json","targetId":"risk:net-poor-perimeter-architecture","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fdf9c0b3bfd1411c02187e9c911797c9442799407d072dc64b61c9804c53441e","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-net-09-6777e6ac.json","targetId":"uc:UC-NET-09","type":"tests"}],"schemaVersion":1}
