Skip to main content
NET

Network Security

103 controls

Architect and implement defense-in-depth network protections that segment, restrict and monitor access to Technology Assets, Applications, Services and Data (TAASD).

SCF # Control Name Weight NIST CSF Frameworks
NET-01 Network Security Policy 10 — Critical Govern 3
NET-02 Network Security Controls (NSC) 10 — Critical Govern 97
NET-03 Boundary Protection 10 — Critical Protect 87
NET-03.1 Limit Network Connections 9 — Critical Protect 32
NET-03.2 External Telecommunications Services 7 — High Protect 20
NET-03.3 Prevent Discovery of Internal Information 7 — High Protect 12
NET-03.4 Direct Internet Access Restrictions 6 — Medium Protect 13
NET-03.5 Prevent Unauthorized Exfiltration 5 — Medium Protect 21
NET-03.6 Protocol Compliance Enforcement 5 — Medium Protect 1
NET-03.7 Domain Name Verification 8 — High Protect 1
NET-03.8 Bandwidth Control 2 — Low Protect 1
NET-03.9 Internet Address Denylisting 8 — High Protect 1
NET-03.10 Certificate Denylisting 7 — High Protect 1
NET-03.11 Content Disarm and Reconstruction (CDR) 6 — Medium Protect 1
NET-03.12 Network Processing Rules For Personal Data (PD) 7 — High Protect 7
NET-03.13 Split Tunneling 8 — High Protect 30
NET-04 Data Flow Enforcement – Access Control Lists (ACLs) 10 — Critical Protect 75
NET-04.1 Deny Traffic by Default & Allow Traffic by Exception 10 — Critical Protect 59
NET-04.2 Human Reviews 9 — Critical Detect 11
NET-05 Interconnection Security Agreements (ISAs) 9 — Critical Protect 44
NET-05.1 External System Connections 8 — High Protect 15
NET-05.2 Internal System Connections 7 — High Protect 34
NET-06 Network Segmentation (macrosegmentation) 10 — Critical Protect 87
NET-06.1 Security Management Subnets 9 — Critical Protect 29
NET-07 Out-of-Band Channels 9 — Critical Protect 9
NET-08 Separate Subnets To Isolate Functions 7 — High Protect 5
NET-08.1 Sensitive / Regulated Data Enclave (Secure Zone) 10 — Critical Protect 14
NET-08.2 Segregation From Enterprise Services 4 — Medium Protect 7
NET-09 Network Device Plane Segmentation 7 — High Protect 1
NET-10 Virtual Local Area Network (VLAN) Separation 9 — Critical Protect 3
NET-11 Microsegmentation 2 — Low Protect 7
NET-12 Software Defined Networking (SDN) 5 — Medium Protect 2
NET-13 Domain Name Service (DNS) Resolution 10 — Critical Protect 40
NET-13.1 Architecture & Provisioning for Name / Address Resolution Service 9 — Critical Protect 28
NET-13.2 Secure Name / Address Resolution Service (Recursive or Caching Resolver) 9 — Critical Protect 30
NET-13.3 Domain Registrar Security 9 — Critical Protect 3
NET-14 Zero Trust Architecture (ZTA) 8 — High Protect 17
NET-15 Policy Decision Point (PDP) 5 — Medium Protect 17
NET-16 Network Access Control (NAC) 4 — Medium Protect 17
NET-17 DNS & Content Filtering 9 — Critical Protect 50
NET-18 Authenticated Proxy 3 — Low Protect 1
NET-18.1 Route Internal Traffic to Proxy Servers 9 — Critical Protect 24
NET-18.2 Route Privileged Network Access 1 — Low Detect 4
NET-19 Application Proxy 7 — High Protect 0
NET-20 Visibility of Encrypted Communications 5 — Medium Detect 11
NET-20.1 Content Check for Encrypted Data 4 — Medium Protect 6
NET-21 Denial of Service (DoS) Protection 9 — Critical Protect 40
NET-22 Guest Networks 6 — Medium Protect 19
NET-23 Intranets 8 — High Protect 0
NET-24 Wireless Networking 9 — Critical Protect 56
NET-24.1 Wireless Networking Authentication & Encryption 9 — Critical Protect 39
NET-24.2 Wireless Boundaries 5 — Medium Protect 10
NET-25 Rogue Wireless Detection 8 — High Detect 9
NET-26 Remote Access 10 — Critical Protect 84
NET-26.1 Remote Access Pathways 9 — Critical Protect 35
NET-26.2 Expeditious Remote Access Disconnect / Disable Capability 8 — High Protect 15
NET-26.3 Remote Access Endpoint Security Validation 6 — Medium Protect 15
NET-26.4 Remote Access Monitoring & Control 1 — Low Detect 36
NET-26.5 Remote Access Cryptographic Protections 9 — Critical Protect 39
NET-26.6 Remote Access Privileged Commands & Sensitive Data Access 8 — High Protect 30
NET-27 Work From Anywhere (WFA) - Telecommuting Security 10 — Critical Protect 27
NET-28 Network Connection Termination 8 — High Protect 36
NET-29 Session Integrity 8 — High Protect 38
NET-30 Third-Party Remote Access Governance 8 — High Protect 11
NET-31 Network Intrusion Detection / Prevention Systems (NIDS / NIPS) 9 — Critical Protect 43
NET-32 Wireless Intrusion Detection / Prevention Systems (WIDS / WIPS) Deployment 8 — High Protect 11
NET-33 Demilitarized Zones (DMZ) 9 — Critical Protect 18
NET-34 Web Application Firewall (WAF) 8 — High Protect 20
NET-35 Application Programming Interface (API) Security 9 — Critical Protect 14
NET-36 API Gateway 7 — High Protect 2
NET-37 Safeguarding Data Over Open Networks 8 — High Protect 47
NET-38 Wireless Link Protection 8 — High Protect 16
NET-39 Email Domain Reputation Protections 1 — Low Protect 1
NET-39.1 Domain-Based Message Authentication Reporting and Conformance (DMARC) 3 — Low Protect 10
NET-39.2 Sender Policy Framework (SPF) 8 — High Protect 11
NET-39.3 Authenticated Received Chain (ARC) 2 — Low Protect 1
NET-39.4 Sender Denylisting 7 — High Protect 1
NET-40 End-User Messaging Technologies 9 — Critical Protect 9
NET-40.1 Electronic Messaging 10 — Critical Protect 17
NET-40.2 Phishing & Spam Protection 10 — Critical Protect 42
NET-40.3 Email Content Protections 10 — Critical Protect 1
NET-40.4 Adaptive Email Protections 1 — Low Protect 6
NET-40.5 Email Labeling 5 — Medium Protect 1
NET-40.6 User Digital Signatures for Outgoing Email 6 — Medium Protect 1
NET-40.7 Encryption for Outgoing Email 6 — Medium Protect 1
NET-40.8 User Threat Reporting 1 — Low Protect 1
NET-41 Cross Domain Solution (CDS) 6 — Medium Protect 14
NET-41.1 Separate Subnet for Connecting to Different Security Domains 5 — Medium Protect 18
NET-41.2 Cross Domain Authentication 5 — Medium Protect 7
NET-41.3 Data Type Identifiers 5 — Medium Protect 6
NET-41.4 Decomposition Into Policy-Related Subcomponents 5 — Medium Protect 5
NET-41.5 Detection of Unsanctioned Information 5 — Medium Detect 5
NET-42 Cross Domain Content Transfer 5 — Medium Protect 6
NET-42.1 Isolation of System Components 5 — Medium Protect 26
NET-42.2 Dynamic Isolation & Segregation (Sandboxing) 5 — Medium Protect 10
NET-43 Host Containment 3 — Low Protect 8
NET-44 Resource Containment 3 — Low Protect 3
NET-45 Conceal / Randomize Communications 5 — Medium Protect 4
NET-45.1 Object Security Attributes 5 — Medium Protect 5
NET-45.2 Embedded Data Types 2 — Low Protect 3
NET-46 Metadata 2 — Low Protect 11
NET-46.1 Metadata Validation 2 — Low Protect 5
NET-47 Side Channel Attack Prevention 3 — Low Protect 5

The Secure Controls Framework (SCF) is maintained by SCF Council. Use of SCF content is subject to the SCF Terms & Conditions.

Manage SCF Controls in SCF Connect

Streamline your compliance program with automated control tracking, evidence management, and framework mapping.