Sekit CSF · Familia
Network Security
24 controles en 8 temas, cada uno visto a través de las lentes de política, proceso y técnica.
Política
RCF-0178Email security4 mapeosFormal controls are required to protect against phishing, spoofing and malicious email contentRCF-0172Firewall management5 mapeosFormal policies govern which network traffic is permitted and how firewall rules are created and reviewedRCF-0169Network segmentation4 mapeosThe company formally divides its network into zones to limit the spread of threats between systemsRCF-0175Secure DNS4 mapeosThe company formally requires that domain name resolution is protected against manipulation and abuseRCF-0181TLS termination/hardening4 mapeosThe company formally requires that encrypted communications use strong protocols and current cipher suitesRCF-0187VPN management4 mapeosRemote network access through virtual private networks is formally governed and restricted to approved users and devicesRCF-0190Wireless security4 mapeosThe company formally defines security requirements for all wireless networks it operates or permitsRCF-0184Zero Trust network access5 mapeosThe company formally adopts the principle that no user or device is trusted by default regardless of network location
Proceso
RCF-0179Email security4 mapeosEmail security controls are consistently maintained and suspicious emails are investigated and reportedRCF-0173Firewall management5 mapeosFirewall rules are consistently reviewed and unused or overly permissive rules are removedRCF-0170Network segmentation4 mapeosNetwork zones are consistently maintained and traffic between them is controlled and reviewedRCF-0176Secure DNS4 mapeosDNS configurations are consistently reviewed and DNS traffic is monitored for malicious activityRCF-0182TLS termination/hardening4 mapeosTLS configurations are consistently reviewed and weak protocols or ciphers are disabledRCF-0188VPN management4 mapeosVPN access is consistently provisioned, reviewed and removed when no longer requiredRCF-0191Wireless security5 mapeosWireless networks are consistently configured to security standards and unauthorised access points are identifiedRCF-0185Zero Trust network access6 mapeosZero trust access principles are consistently applied and all access requests are verified before being granted
Técnica
RCF-0180Email security4 mapeosTechnical tools enforce SPF, DKIM, DMARC and scan incoming email for malicious links and attachmentsRCF-0174Firewall management6 mapeosTechnical tools manage firewall rule sets and alert on changes or rules that conflict with security policyRCF-0171Network segmentation5 mapeosTechnical controls enforce network boundaries and restrict traffic between zones based on policyRCF-0177Secure DNS4 mapeosTechnical controls implement DNS filtering, DNSSEC and monitoring to detect and block malicious domainsRCF-0183TLS termination/hardening4 mapeosTechnical controls enforce TLS version and cipher standards across all services and flag non-compliant endpointsRCF-0189VPN management7 mapeosTechnical controls enforce authentication, encryption and access policy for all VPN connectionsRCF-0192Wireless security6 mapeosTechnical controls enforce wireless encryption, segment guest networks and detect rogue access pointsRCF-0186Zero Trust network access7 mapeosTechnical controls enforce continuous verification of identity and device health before granting network access
Esta familia en ISO/IEC 27001:2022
Cada elemento de marco al que mapean los controles de la familia, primero los más conectados; agrupado por familia del Sekit CSF, nunca por el índice del propio marco.
Esta familia en NIST CSF 2.0
Esta familia en Cyber Essentials
Pregúntale a Sekura: «¿Qué evidencia demuestra Network Security?»
También vía MCP, gratis con cuenta