{"data":{"id":"SC-07","name":"Boundary Protection","family":"SC","family_name":"System and Communications Protection","withdrawn":false,"description":"a. Monitor and control communications at the external managed interfaces to the system and at key internal managed interfaces within the system;\nb. Implement subnetworks for publicly accessible system components that are [Selection (one): physically; logically] separated from internal organizational networks; and\nc. Connect to external networks or systems only through managed interfaces consisting of boundary protection devices arranged in accordance with an organizational security and privacy architecture.","supplemental_guidance":"Managed interfaces include gateways, routers, firewalls, guards, network-based malicious code analysis, virtualization systems, or encrypted tunnels implemented within a security architecture. Subnetworks that are physically or logically separated from internal networks are referred to as demilitarized zones or DMZs. Restricting or prohibiting interfaces within organizational systems includes restricting external web traffic to designated web servers within managed interfaces, prohibiting external traffic that appears to be spoofing internal addresses, and prohibiting internal traffic that appears to be spoofing external addresses. [SP 800-189] provides additional information on source address validation techniques to prevent ingress and egress of traffic with spoofed addresses. Commercial telecommunications services are provided by network components and consolidated management systems shared by customers. These services may also include third party-provided access lines and other service elements. Such services may represent sources of increased risk despite contract security provisions. Boundary protection may be implemented as a common control for all or part of an organizational network such that the boundary to be protected is greater than a system-specific boundary (i.e., an authorization boundary).","enhancements":[{"id":"SC-07(01)","name":"Physically Separated Subnetworks","withdrawn":true,"incorporated_into":["SC-07"]},{"id":"SC-07(02)","name":"Public Access","withdrawn":true,"incorporated_into":["SC-07"]},{"id":"SC-07(03)","name":"Access Points","statement":"Limit the number of external network connections to the system.","baselines":["moderate","high"]},{"id":"SC-07(04)","name":"External Telecommunications Services","statement":"a. Implement a managed interface for each external telecommunication service;\nb. Establish a traffic flow policy for each managed interface;\nc. Protect the confidentiality and integrity of the information being transmitted across each interface;\nd. Document each exception to the traffic flow policy with a supporting mission or business need and duration of that need;\ne. Review exceptions to the traffic flow policy [Assignment: organization-defined frequency] and remove exceptions that are no longer supported by an explicit mission or business need;\nf. Prevent unauthorized exchange of control plane traffic with external networks;\ng. Publish information to enable remote networks to detect unauthorized control plane traffic from internal networks; and\nh. Filter unauthorized control plane traffic from external networks.","baselines":["moderate","high"]},{"id":"SC-07(05)","name":"Deny by Default — Allow by Exception","statement":"Deny network communications traffic by default and allow network communications traffic by exception [Selection (one or more): at managed interfaces; for [Assignment: organization-defined systems]].","baselines":["moderate","high"]},{"id":"SC-07(06)","name":"Response to Recognized Failures","withdrawn":true,"incorporated_into":["SC-07(18)"]},{"id":"SC-07(07)","name":"Split Tunneling for Remote Devices","statement":"Prevent split tunneling for remote devices connecting to organizational systems unless the split tunnel is securely provisioned using [Assignment: organization-defined safeguards].","baselines":["moderate","high"]},{"id":"SC-07(08)","name":"Route Traffic to Authenticated Proxy Servers","statement":"Route [Assignment: organization-defined internal communications traffic] to [Assignment: organization-defined external networks] through authenticated proxy servers at managed interfaces.","baselines":["moderate","high"]},{"id":"SC-07(09)","name":"Restrict Threatening Outgoing Communications Traffic","statement":"a. Detect and deny outgoing communications traffic posing a threat to external systems; and\nb. Audit the identity of internal users associated with denied communications.","baselines":[]},{"id":"SC-07(10)","name":"Prevent Exfiltration","statement":"a. Prevent the exfiltration of information; and\nb. Conduct exfiltration tests [Assignment: organization-defined frequency].","baselines":[]},{"id":"SC-07(11)","name":"Restrict Incoming Communications Traffic","statement":"Only allow incoming communications from [Assignment: organization-defined authorized sources] to be routed to [Assignment: organization-defined authorized destinations].","baselines":[]},{"id":"SC-07(12)","name":"Host-based Protection","statement":"Implement [Assignment: organization-defined host-based boundary protection mechanisms] at [Assignment: organization-defined system components].","baselines":[]},{"id":"SC-07(13)","name":"Isolation of Security Tools, Mechanisms, and Support Components","statement":"Isolate [Assignment: organization-defined information security tools, mechanisms, and support components] from other internal system components by implementing physically separate subnetworks with managed interfaces to other components of the system.","baselines":[]},{"id":"SC-07(14)","name":"Protect Against Unauthorized Physical Connections","statement":"Protect against unauthorized physical connections at [Assignment: organization-defined managed interfaces].","baselines":[]},{"id":"SC-07(15)","name":"Networked Privileged Accesses","statement":"Route networked, privileged accesses through a dedicated, managed interface for purposes of access control and auditing.","baselines":[]},{"id":"SC-07(16)","name":"Prevent Discovery of System Components","statement":"Prevent the discovery of specific system components that represent a managed interface.","baselines":[]},{"id":"SC-07(17)","name":"Automated Enforcement of Protocol Formats","statement":"Enforce adherence to protocol formats.","baselines":[]},{"id":"SC-07(18)","name":"Fail Secure","statement":"Prevent systems from entering unsecure states in the event of an operational failure of a boundary protection device.","baselines":["high"]},{"id":"SC-07(19)","name":"Block Communication from Non-organizationally Configured Hosts","statement":"Block inbound and outbound communications traffic between [Assignment: organization-defined communication clients] that are independently configured by end users and external service providers.","baselines":[]},{"id":"SC-07(20)","name":"Dynamic Isolation and Segregation","statement":"Provide the capability to dynamically isolate [Assignment: organization-defined system components] from other system components.","baselines":[]},{"id":"SC-07(21)","name":"Isolation of System Components","statement":"Employ boundary protection mechanisms to isolate [Assignment: organization-defined system components] supporting [Assignment: organization-defined missions and/or business functions].","baselines":["high"]},{"id":"SC-07(22)","name":"Separate Subnets for Connecting to Different Security Domains","statement":"Implement separate network addresses to connect to systems in different security domains.","baselines":[]},{"id":"SC-07(23)","name":"Disable Sender Feedback on Protocol Validation Failure","statement":"Disable feedback to senders on protocol format validation failure.","baselines":[]},{"id":"SC-07(24)","name":"Personally Identifiable Information","statement":"For systems that process personally identifiable information:\na. Apply the following processing rules to data elements of personally identifiable information: [Assignment: organization-defined processing rules];\nb. Monitor for permitted processing at the external interfaces to the system and at key internal boundaries within the system;\nc. Document each processing exception; and\nd. Review and remove exceptions that are no longer supported.","baselines":["privacy"]},{"id":"SC-07(25)","name":"Unclassified National Security System Connections","statement":"Prohibit the direct connection of [Assignment: organization-defined unclassified national security system] to an external network without the use of [Assignment: organization-defined boundary protection device].","baselines":[]},{"id":"SC-07(26)","name":"Classified National Security System Connections","statement":"Prohibit the direct connection of a classified national security system to an external network without the use of [Assignment: organization-defined boundary protection device].","baselines":[]},{"id":"SC-07(27)","name":"Unclassified Non-national Security System Connections","statement":"Prohibit the direct connection of [Assignment: organization-defined unclassified non-national security system] to an external network without the use of [Assignment: organization-defined boundary protection device].","baselines":[]},{"id":"SC-07(28)","name":"Connections to Public Networks","statement":"Prohibit the direct connection of [Assignment: organization-defined system] to a public network.","baselines":[]},{"id":"SC-07(29)","name":"Separate Subnets to Isolate Functions","statement":"Implement [Selection (one): physically; logically] separate subnetworks to isolate the following critical system components and functions: [Assignment: organization-defined critical system components and functions].","baselines":[]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"SC-07","name":"Boundary Protection","description":"a. Monitor and control communications at the external managed interfaces to the system and at key internal managed interfaces within the system;\nb. Implement subnetworks for publicly accessible system components that are [Selection (one): physically; logically] separated from internal organizational networks; and\nc. Connect to external networks or systems only through managed interfaces consisting of boundary protection devices arranged in accordance with an organizational security and privacy architecture.","discussion":"Managed interfaces include gateways, routers, firewalls, guards, network-based malicious code analysis, virtualization systems, or encrypted tunnels implemented within a security architecture. Subnetworks that are physically or logically separated from internal networks are referred to as demilitarized zones or DMZs. Restricting or prohibiting interfaces within organizational systems includes restricting external web traffic to designated web servers within managed interfaces, prohibiting external traffic that appears to be spoofing internal addresses, and prohibiting internal traffic that appears to be spoofing external addresses. [SP 800-189] provides additional information on source address validation techniques to prevent ingress and egress of traffic with spoofed addresses. Commercial telecommunications services are provided by network components and consolidated management systems shared by customers. These services may also include third party-provided access lines and other service elements. Such services may represent sources of increased risk despite contract security provisions. Boundary protection may be implemented as a common control for all or part of an organizational network such that the boundary to be protected is greater than a system-specific boundary (i.e., an authorization boundary).","related_controls":["AC-04","AC-17","AC-18","AC-19","AC-20","AU-13","CA-03","CM-02","CM-04","CM-07","CM-10","CP-08","CP-10","IR-04","MA-04","PE-03","PL-08","PM-12","SA-08","SA-17","SC-05","SC-26","SC-32","SC-35","SC-43"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"Control text changes 'boundary' to 'managed interfaces; adds 'and privacy' in reference to organizational security architecture"}},"compliance_mappings":{"iso_27001_2022":["A.5.14","A.5.23","A.8.12","A.8.16","A.8.20","A.8.21","A.8.22","A.8.23","A.8.27"],"iso_27002_2022":["5.14","5.23","8.12","8.20","8.21","8.22","8.23","8.27"],"cobit_2019":["DSS05"],"pci_dss_v4":["1.1","1.2","1.2.1","1.2.5","1.3","1.4","1.5","5.4","6.4"],"nist_csf_2":["DE.CM-01","ID.AM-03","PR.DS-01","PR.DS-02","PR.DS-10","PR.IR-01","RS.MI-01"],"cis_controls_v8":["CIS 3.12","CIS 3.13","CIS 4","CIS 4.2","CIS 4.4","CIS 4.5","CIS 9","CIS 9.2","CIS 9.3","CIS 9.6","CIS 12","CIS 12.2","CIS 12.8","CIS 13","CIS 13.3","CIS 13.4","CIS 13.8","CIS 13.9","CIS 13.10"],"soc2_tsc":["CC6.1","CC6.1-POF5","CC6.6","CC6.6-POF1","CC6.6-POF3","CC6.8"],"finos_ccc":["CCC-C05","CCC-C09"],"iso_42001_2023":[],"iec_62443":["3-3 SR 5.1","3-3 SR 5.2"],"asd_e8":["E8-5 ML2"],"nis2":[],"apra_cps_234":["Para 22-23"],"mas_trm":["11","14","15"],"pra_op_resilience":["SS2/21-14.1"],"bsi_grundschutz":["APP.3.1","NET.1.1","NET.1.2","NET.3.1"],"anssi":["Hygiene.22","Hygiene.23","Hygiene.27","SecNumCloud.14.1","SecNumCloud.14.4"],"osfi_b13":["B-13.3.2"],"finma_circular":["IV.B.d(59)","IV.C(62)","IV.C(63)"],"gdpr":["Art.5(1)(f)","Art.32(1)(a)","Art.32(1)(b)"],"dora":["Art.9(4)(a)"],"bio2":["5.14","5.23","8.12","8.20","8.21","8.22","8.23","8.27"],"rbi_csf":["Annex1.4","Annex1.15","ITGRCA.19"],"fisc":["FISC.T3","FISC.T8","FISC.T9","FISC.T10","FISC.T11","FISC.T13"],"lgpd_bcb":["BCB.Art.3","BCB.Art.13","BCB.OpenFinance","BCB.PIX","LGPD.Art.46"],"hkma_tme1":["TME1.7.3","TME1.10.1","TME1.10.3","TME1.12.4"],"mlps_2":["8.1.2.1","8.1.3.1","8.1.3.2","8.1.3.3","8.2","8.3","8.5"],"dnb_good_practice":["DNB.18.1","DNB.18.4","DNB.20.1"],"cra":["CRA.I.2i","CRA.I.2j"],"swift_cscf":["SWIFT.1.1","SWIFT.1.3","SWIFT.1.4","SWIFT.1.5","SWIFT.2.3","SWIFT.6.5A"],"cbb_tm":["TM-8"],"cbuae":["CR-7"],"nca_ecc":["2-3","2-4","2-5","2-14","4-2","5-1"],"qatar_nia":["CS"],"sama_csf":["2.1","3.3","4.3"],"uae_ia":["T8"],"bog_cisd":["CISD-IX","CISD-VI","CISD-VIII","CISD-XI","CISD-XII","CISD-XIII"],"bom_ctrm":["3.2","3.13"],"cbe_csf":["CRM-2","CTO-5","CTO-6","CTO-8","CTO-11"],"cbn_csf":["Part3.1","Part3.3","Part5.1","Part5.2"],"popia":["s19","s72"],"sa_js2":["JS2-7.2","JS2-7.6"],"bcbs_239":["Principle 2"],"bot_cyber":["Ch2.4","Ch5.2","Ch8.2","Ch9.1"],"cpmi_pfmi":["CG.DE","CG.PR","PFMI.P17","PFMI.P22"],"eba_ict":["3.4.4"],"ecb_croe":["CROE.2.3.5","CROE.2.4"],"ffiec_is":["II.C.2","II.C.6","II.C.9","II.C.12","II.C.16"],"hipaa_sr":["§164.308(a)(4)(ii)(A)","§164.312(e)(1)","§164.314(b)(1)","§164.314(b)(2)"],"iosco_cyber":["DET-4","PFMI-20","PROT-2"],"nydfs_500":["500.2","500.14"],"sebi_cscrf":["EMAIL-SEC","PR.CS","PR.NS"],"cmmc_2":["SC"],"nerc_cip":["CIP-002-7","CIP-005-7","CIP-015-1"],"nrc_73_54":["73.54(c)(1)","73.54(c)(2)","RG5.71-A-SC"],"tsa_psd":["SD-2 Sec A","SD-2 Sec F"],"ieee_1686":["5.6"],"ferc_cip":["Order 881","Order 887","Order 2222"],"doe_c2m2":["ARCHITECTURE"],"api_1164":["Sec 5"],"awia":["AWWA Sec 4"],"iaea_nss":["Sec 5.1","Sec 5.6"],"pci_pts":["E"],"fips_140":["FIPS 140-3 §7.3"],"cbest":["CBEST.5"],"tiber_eu":[],"pci_hsm":[],"common_criteria":["CC Part 2 — FDP","CC Part 2 — FPT"],"isae_3402":["Clause 4"],"fca_sysc_13":["SYSC 13.7.3"],"fda_21_cfr_11":["§11.30"],"fda_cyber":["PU-3","TM-2"],"hitrust_csf":["01.b","01.d","05.c","09.e"],"iso_27799":["13.1","H.2","H.3"],"lloyds_ms":["MS8.9"],"naic_ds":["4","4-monitoring","4B"],"nhs_dspt":["NDG-9.2","NDG-9.4","NDG-9.5"],"pra_ss1_23":["P-IT.3"],"solvency_ii":["EIOPA-ICT-4.6"],"owasp_masvs_v2":["MASVS-NETWORK-1","MASVS-PLATFORM-1","MASVS-PLATFORM-2"],"csa_ccm_v4":["IVS-03","IVS-05","IVS-06","IVS-08","IVS-09","UEM-10","UEM-11"],"csa_aicm":["AIS-08","I&S-03","I&S-05","I&S-06","I&S-08","I&S-09","IAM-17","UEM-10","UEM-11"],"ccss_v9":[],"mica":["Art.62(5)","Art.68(1)"],"basel_sco60":["SCO60.21","SCO60.41","SCO60.51","SCO60.64","SCO60.65"],"bssc":["NOS-04","TIS-04"],"sec_custody_digital":["SEC-CD-09"],"dpdpa":["Act.8(5)","Rules.13(4)","Rules.Sch1.B.7"]},"attack_techniques":[{"id":"T1001","name":"Data Obfuscation","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection devices with deep-packet inspection can detect obfuscated C2 data traversing network perimeters by analyzing traffic content for anomalous encoding patterns and protocol deviations that indicate covert command channels."},{"id":"T1008","name":"Fallback Channels","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network boundary controls can disrupt fallback C2 channels by enforcing strict egress filtering that blocks unauthorized outbound connections, preventing adversaries from establishing alternative communication paths when primary channels fail."},{"id":"T1029","name":"Scheduled Transfer","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection with traffic-pattern analysis can detect scheduled exfiltration by identifying periodic outbound data transfers that match automated staging-and-transfer patterns inconsistent with normal business communications."},{"id":"T1030","name":"Data Transfer Size Limits","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Network boundary monitoring can detect size-limited exfiltration by correlating multiple small outbound transfers to the same destination, identifying adversary techniques designed to stay below data-loss-prevention thresholds."},{"id":"T1041","name":"Exfiltration Over C2 Channel","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection devices can detect and block exfiltration over C2 channels by inspecting outbound traffic for data payloads embedded within established command-and-control connections traversing the network perimeter."},{"id":"T1046","name":"Network Service Discovery","tactics":["discovery"],"mapping_type":"mitigates","mapping_rationale":"Network boundary segmentation limits the scope of service discovery by restricting cross-zone visibility, preventing adversaries from scanning services in protected network segments from less-trusted zones."},{"id":"T1048","name":"Exfiltration Over Alternative Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection with strict egress filtering can block exfiltration over alternative protocols by restricting outbound traffic to authorized protocols and ports, preventing data theft over DNS, ICMP, or other unexpected channels."},{"id":"T1055","name":"Process Injection","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Network boundary segmentation limits the impact of process injection by containing compromised processes within their network zone, preventing injected code from accessing resources in higher-trust segments."},{"id":"T1068","name":"Exploitation for Privilege Escalation","tactics":["privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Network boundary controls limit the exploitability of privilege-escalation vulnerabilities by restricting network access to vulnerable services, reducing the attack surface available for exploitation from less-trusted zones."},{"id":"T1071","name":"Application Layer Protocol","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection devices with application-layer inspection can detect C2 traffic disguised within HTTP, DNS, SMTP, and other protocols by analyzing content for anomalous payloads that deviate from legitimate protocol usage."},{"id":"T1072","name":"Software Deployment Tools","tactics":["execution","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation restricts software deployment tool access to authorized zones, preventing adversaries from leveraging compromised deployment infrastructure to execute code or move laterally across network boundaries."},{"id":"T1078","name":"Valid Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection limits the utility of compromised valid accounts by enforcing network-level access controls that restrict which systems can be reached from specific zones, regardless of authentication credentials."},{"id":"T1080","name":"Taint Shared Content","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation limits the propagation of tainted shared content by restricting cross-zone file-share access, preventing poisoned files from reaching systems in separate network segments."},{"id":"T1090","name":"Proxy","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection devices can detect and block proxy-based C2 infrastructure by identifying unauthorized proxy connections at network perimeters and enforcing policies against unapproved relay traffic."},{"id":"T1095","name":"Non-Application Layer Protocol","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network boundary controls can block non-application-layer C2 protocols by filtering ICMP, raw sockets, and custom protocols at perimeter firewalls, preventing covert channels that bypass application-layer inspection."},{"id":"T1098","name":"Account Manipulation","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation restricts the reach of account manipulation by limiting access to identity management systems, preventing adversaries in low-trust zones from modifying accounts in protected directory services."},{"id":"T1102","name":"Web Service","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection with URL filtering and web proxies can restrict connections to web services used for C2 by blocking access to unauthorized cloud storage, social media APIs, and paste sites from protected networks."},{"id":"T1104","name":"Multi-Stage Channels","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network boundary controls can disrupt multi-stage C2 by blocking callback connections to secondary staging infrastructure, preventing adversaries from establishing layered command channels across the perimeter."},{"id":"T1105","name":"Ingress Tool Transfer","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection with egress and ingress filtering can block tool transfer by restricting file downloads from unauthorized sources and preventing the introduction of adversary tools through network boundaries."},{"id":"T1114","name":"Email Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation protects email infrastructure by restricting access to mail servers and limiting email collection to authorized email clients and management systems within approved network zones."},{"id":"T1132","name":"Data Encoding","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection with traffic inspection can detect encoded C2 data at network perimeters by identifying Base64, XOR, or custom encoding in protocol fields traversing the boundary."},{"id":"T1133","name":"External Remote Services","tactics":["initial-access","persistence"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection is a primary control against abuse of external remote services by restricting VPN, RDP, and SSH access through managed interfaces with authentication, monitoring, and access-control enforcement."},{"id":"T1136","name":"Create Account","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation limits the impact of unauthorized account creation by restricting access to directory services and identity providers, preventing adversaries from creating accounts across network boundaries."},{"id":"T1176","name":"Browser Extensions","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection with web filtering can limit malicious browser extension activity by blocking connections to C2 infrastructure and data-exfiltration endpoints that extensions attempt to reach across the network perimeter."},{"id":"T1187","name":"Forced Authentication","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Network boundary controls can prevent forced-authentication credential theft by blocking outbound SMB, WebDAV, and similar authentication traffic to untrusted destinations, preventing NTLM hash interception."},{"id":"T1189","name":"Drive-by Compromise","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection with web proxies and URL filtering can mitigate drive-by compromises by blocking access to known malicious websites, exploit kit landing pages, and watering-hole domains."},{"id":"T1190","name":"Exploit Public-Facing Application","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection is a frontline defense against exploitation of public-facing applications by filtering malicious inbound traffic, enforcing web application firewall rules, and limiting exposed attack surface."},{"id":"T1197","name":"BITS Jobs","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Network boundary controls can limit BITS job abuse by restricting outbound BITS transfer destinations through proxy enforcement, preventing adversaries from using BITS for data exfiltration or tool download."},{"id":"T1199","name":"Trusted Relationship","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection controls access from trusted third-party connections by enforcing dedicated managed interfaces, segmentation, and monitoring for traffic from business partners and service providers."},{"id":"T1203","name":"Exploitation for Client Execution","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Network boundary protection at web proxies can reduce exploitation for client execution by blocking access to websites hosting exploit kits and filtering malicious content before it reaches client applications."},{"id":"T1204","name":"User Execution","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection with content filtering can reduce user execution of malicious content by blocking downloads of dangerous file types and restricting access to known malicious distribution points."},{"id":"T1205","name":"Traffic Signaling","tactics":["command-and-control","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Network boundary devices can detect and block traffic signaling techniques—including port knocking—by enforcing strict stateful inspection that rejects connection attempts not matching authorized traffic patterns."},{"id":"T1210","name":"Exploitation of Remote Services","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation is a primary defense against exploitation of remote services for lateral movement by isolating systems into zones and restricting cross-zone access to only authorized service connections."},{"id":"T1211","name":"Exploitation for Defense Evasion","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection limits exploitation for defense evasion by restricting the attack surface accessible from less-trusted zones, reducing opportunities for adversaries to exploit vulnerabilities that disable security controls."},{"id":"T1212","name":"Exploitation for Credential Access","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation restricts exploitation for credential access by isolating authentication infrastructure in protected zones, limiting adversary access to credential-storage services from compromised segments."},{"id":"T1218","name":"System Binary Proxy Execution","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection can limit the impact of system binary proxy execution by blocking outbound connections from LOLBin processes to unauthorized external resources through strict egress filtering."},{"id":"T1219","name":"Remote Access Software","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network boundary controls can detect and block unauthorized remote access software by identifying RAS connection patterns at perimeter firewalls and restricting outbound connections to unapproved remote-access services."},{"id":"T1221","name":"Template Injection","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection with web filtering can block template injection by preventing Office documents from retrieving remote templates from unauthorized external servers during document opening."},{"id":"T1482","name":"Domain Trust Discovery","tactics":["discovery"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation limits domain trust discovery by restricting LDAP and domain-controller access across zone boundaries, preventing adversaries from enumerating trust relationships from compromised segments."},{"id":"T1489","name":"Service Stop","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Network boundary controls protect critical services by restricting access to service-management interfaces, preventing adversaries in less-trusted zones from stopping services across network boundaries."},{"id":"T1498","name":"Network Denial of Service","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection devices—including rate-limiting firewalls, scrubbing services, and traffic-filtering appliances—are primary defenses against network DoS attacks by absorbing and filtering volumetric attack traffic."},{"id":"T1499","name":"Endpoint Denial of Service","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Network boundary protection with rate limiting and traffic shaping can mitigate endpoint DoS attacks by throttling excessive request rates before they overwhelm target services behind the perimeter."},{"id":"T1530","name":"Data from Cloud Storage","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Network boundary controls can restrict unauthorized access to cloud storage by enforcing CASB policies and limiting which network zones can reach cloud-storage APIs, preventing data collection from unsanctioned access paths."},{"id":"T1537","name":"Transfer Data to Cloud Account","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection with egress controls can detect data transfer to external cloud accounts by monitoring for unusual outbound connections to cloud storage APIs and blocking unauthorized cross-account data movements."},{"id":"T1542","name":"Pre-OS Boot","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation isolates pre-OS boot management interfaces, restricting access to firmware-update and boot-configuration mechanisms that adversaries could abuse for pre-OS persistence."},{"id":"T1552","name":"Unsecured Credentials","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection limits credential exposure by segmenting credential-storage systems within protected zones, reducing the attack surface available for adversaries to access unsecured credential repositories."},{"id":"T1557","name":"Adversary-in-the-Middle","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation with managed interfaces limits adversary-in-the-middle opportunities by isolating network segments, reducing the scope within which ARP poisoning, DHCP spoofing, and similar interception techniques can operate."},{"id":"T1559","name":"Inter-Process Communication","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Network boundary controls can limit inter-process communication abuse by restricting DCOM and other IPC protocols at zone boundaries, preventing cross-zone exploitation of COM/DDE interfaces."},{"id":"T1560","name":"Archive Collected Data","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection with DLP capabilities can detect archived data being staged for exfiltration by inspecting outbound transfers for compressed and encrypted archives containing sensitive content."},{"id":"T1563","name":"Remote Service Session Hijacking","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation restricts remote service session hijacking by limiting cross-zone access to remote-management protocols, preventing adversaries from hijacking sessions across network boundaries."},{"id":"T1565","name":"Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Network boundary controls protect data integrity by restricting access to critical data stores, preventing unauthorized modifications from compromised systems in less-trusted network segments."},{"id":"T1566","name":"Phishing","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection at email gateways and web proxies provides defense against phishing by scanning inbound emails, blocking malicious attachments and URLs, and filtering access to phishing infrastructure."},{"id":"T1567","name":"Exfiltration Over Web Service","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Network boundary controls with egress filtering can detect and block exfiltration to web services by restricting outbound connections to unauthorized cloud storage, paste sites, and code repositories."},{"id":"T1568","name":"Dynamic Resolution","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection with DNS filtering can disrupt dynamic resolution techniques by blocking DNS queries to known DGA domains and restricting DNS resolution to authorized resolvers."},{"id":"T1570","name":"Lateral Tool Transfer","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation directly limits lateral tool transfer by restricting file-sharing protocols between zones, preventing adversaries from copying tools across network boundaries."},{"id":"T1571","name":"Non-Standard Port","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection with port-based access controls blocks C2 on non-standard ports by enforcing policies that only permit expected protocols on their standard ports, rejecting connections on unauthorized port numbers."},{"id":"T1572","name":"Protocol Tunneling","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network boundary inspection can detect protocol tunneling by analyzing traffic for encapsulation patterns—such as DNS-over-HTTPS or HTTP tunneling—that indicate covert channels embedded within permitted protocols."},{"id":"T1573","name":"Encrypted Channel","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection with TLS inspection capabilities can analyze encrypted C2 channels by decrypting traffic at the perimeter, identifying malicious payloads within sessions that would otherwise be opaque to inspection."},{"id":"T1598","name":"Phishing for Information","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection at email gateways provides defense against phishing-for-information by filtering inbound reconnaissance emails, blocking malicious attachments, and flagging suspicious social-engineering messages."},{"id":"T1599","name":"Network Boundary Bridging","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection directly addresses network boundary bridging by enforcing strict segmentation policies, monitoring for unauthorized route changes, and preventing traffic from bypassing designated network perimeters."},{"id":"T1602","name":"Data from Configuration Repository","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation protects configuration repositories by restricting access to network device management interfaces from authorized management zones only, preventing configuration extraction from less-trusted segments."},{"id":"T1609","name":"Container Administration Command","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection around container orchestration environments restricts container administration command access by enforcing network-level controls that limit which systems can issue commands to container management APIs."},{"id":"T1610","name":"Deploy Container","tactics":["defense-evasion","execution"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation can limit unauthorized container deployment by restricting access to container registries and orchestration APIs, preventing adversaries from deploying malicious containers from compromised zones."},{"id":"T1611","name":"Escape to Host","tactics":["privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Network boundary controls around container infrastructure limit the impact of container escape by ensuring that even if adversaries break out to the host, they cannot easily reach systems in other network segments."},{"id":"T1612","name":"Build Image on Host","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection can restrict access to container build environments by segmenting build infrastructure and limiting which zones can push images to trusted registries."},{"id":"T1613","name":"Container and Resource Discovery","tactics":["discovery"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation limits container discovery by restricting access to container orchestration APIs, preventing adversaries in compromised zones from enumerating container infrastructure across network boundaries."},{"id":"T1622","name":"Debugger Evasion","tactics":["defense-evasion","discovery"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection with behavioral analysis at the perimeter can detect malware employing debugger-evasion techniques by identifying traffic patterns characteristic of analysis-aware malware communicating with C2."},{"id":"T1648","name":"Serverless Execution","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Network boundary controls can restrict serverless function execution by enforcing access policies on cloud function APIs and limiting which network zones can trigger serverless workloads."},{"id":"T1659","name":"Content Injection","tactics":["command-and-control","initial-access"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection with content-inspection capabilities can detect content injection attacks by analyzing inbound traffic for manipulated web content, man-on-the-side injection patterns, and tampered responses."},{"id":"T1001.001","name":"Junk Data","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection with traffic analysis can detect junk-data padding in C2 by identifying statistically anomalous packet sizes at the network perimeter that deviate from expected protocol characteristics."},{"id":"T1001.002","name":"Steganography","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network boundary inspection can detect steganographic C2 by analyzing media-file transfers for embedded data payloads that deviate from expected image, audio, or video content formats."},{"id":"T1001.003","name":"Protocol or Service Impersonation","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection with deep protocol validation can detect protocol impersonation at the perimeter by identifying traffic that superficially resembles legitimate protocols but fails strict compliance checks."},{"id":"T1020.001","name":"Traffic Duplication","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Network boundary monitoring can detect traffic duplication by identifying unauthorized port-mirroring, SPAN configurations, or tap-based exfiltration that copies network traffic to adversary-controlled destinations."},{"id":"T1021.001","name":"Remote Desktop Protocol","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection restricts RDP access by enforcing firewall rules that limit Remote Desktop Protocol connections to authorized source networks and require traversal through secure jump hosts."},{"id":"T1021.002","name":"SMB/Windows Admin Shares","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation restricts SMB and admin-share access by blocking port 445 at zone boundaries, preventing lateral movement via Windows administrative shares between network segments."},{"id":"T1021.003","name":"Distributed Component Object Model","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection can block DCOM-based lateral movement by restricting the dynamic RPC ports used for remote DCOM instantiation at zone boundaries."},{"id":"T1021.005","name":"VNC","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Network boundary controls restrict VNC access by filtering VNC protocol traffic at perimeter firewalls, preventing unauthorized graphical remote-control connections across network boundaries."},{"id":"T1021.006","name":"Windows Remote Management","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection restricts Windows Remote Management by filtering WinRM traffic (ports 5985/5986) at zone boundaries, preventing PowerShell remoting and WMI-over-WinRM lateral movement."},{"id":"T1036.008","name":"Masquerade File Type","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Network boundary content filtering can detect files with masqueraded types by analyzing file content during transfer rather than relying on extensions, identifying executables disguised as documents."},{"id":"T1048.001","name":"Exfiltration Over Symmetric Encrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection with egress filtering can block exfiltration over symmetric-encrypted non-C2 channels by restricting encrypted outbound connections to only authorized destinations and protocols."},{"id":"T1048.002","name":"Exfiltration Over Asymmetric Encrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Network boundary controls can block exfiltration over asymmetric-encrypted channels by restricting TLS/SSH connections to approved external endpoints and detecting unauthorized certificate usage."},{"id":"T1048.003","name":"Exfiltration Over Unencrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection can block unencrypted exfiltration by inspecting plaintext outbound traffic at the perimeter and blocking suspicious data transfers over FTP, HTTP, or other unencrypted protocols."},{"id":"T1055.001","name":"Dynamic-link Library Injection","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation limits the impact of DLL injection by containing compromised processes within their zone, preventing injected code from communicating with C2 infrastructure across network boundaries."},{"id":"T1055.002","name":"Portable Executable Injection","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection limits PE injection impact by restricting outbound communications from compromised processes, containing the network reach of injected portable executable code."},{"id":"T1055.003","name":"Thread Execution Hijacking","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation limits thread-hijacking impact by ensuring that even if thread execution is redirected to malicious code, network-level controls constrain its communication and lateral-movement capabilities."},{"id":"T1055.004","name":"Asynchronous Procedure Call","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection limits the network impact of APC injection by restricting the compromised process's ability to establish outbound connections to C2 infrastructure across zone boundaries."},{"id":"T1055.005","name":"Thread Local Storage","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation constrains TLS-injection impact by limiting network access from the hosting process's zone, reducing the ability of injected code to reach attacker infrastructure."},{"id":"T1055.008","name":"Ptrace System Calls","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection limits the network reach of ptrace-injected code on Linux by enforcing zone-level access controls that restrict outbound connections from compromised processes."},{"id":"T1055.009","name":"Proc Memory","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation contains proc-memory injection impact by restricting network communications from the compromised process's zone, limiting lateral movement and C2 access."},{"id":"T1055.011","name":"Extra Window Memory Injection","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection limits extra-window-memory injection impact by restricting the network capabilities of the host process's zone, preventing injected code from establishing external communications."},{"id":"T1055.012","name":"Process Hollowing","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation limits process-hollowing impact by containing the hollowed process within its network zone, preventing the injected code from communicating with C2 across boundaries."},{"id":"T1055.013","name":"Process Doppelgänging","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection limits process-doppelganging impact by restricting the transacted process's network access through zone-level controls, containing adversary communications."},{"id":"T1055.014","name":"VDSO Hijacking","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation limits VDSO-hijacking impact by constraining the compromised process's network access to its assigned zone, preventing cross-boundary C2 communications."},{"id":"T1071.001","name":"Web Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection with web proxy enforcement can detect and filter HTTP/HTTPS-based C2 by requiring all web traffic through inspected proxy channels, identifying anomalous web-protocol patterns at the perimeter."},{"id":"T1071.002","name":"File Transfer Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network boundary controls can detect FTP/FTPS-based C2 by restricting file-transfer protocol usage to authorized connections and inspecting FTP sessions for command-and-control indicators."},{"id":"T1071.003","name":"Mail Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection at email gateways can detect mail-protocol C2 by analyzing SMTP/IMAP/POP3 traffic for embedded commands and restricting mail-server connections to authorized infrastructure."},{"id":"T1071.004","name":"DNS","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network boundary DNS controls can detect DNS-based C2 by enforcing DNS resolution through organizational resolvers, inspecting queries for tunneling indicators, and blocking direct external DNS access."},{"id":"T1071.005","name":"Publish/Subscribe Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection can detect C2 over publish/subscribe protocols (MQTT, AMQP) by restricting these protocols at perimeter firewalls and monitoring for unauthorized IoT-messaging traffic."},{"id":"T1090.001","name":"Internal Proxy","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation and internal boundary controls can detect internal proxy deployment by identifying unauthorized systems relaying traffic between zones, disrupting adversary-established relay infrastructure."},{"id":"T1090.002","name":"External Proxy","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection with egress controls can block connections to external proxy infrastructure by maintaining blocklists of known proxy services and detecting unauthorized encrypted-tunnel establishment."},{"id":"T1090.003","name":"Multi-hop Proxy","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network boundary monitoring can detect multi-hop proxy chains by identifying traffic patterns where connections traverse multiple intermediary nodes, characteristic of adversary obfuscation techniques."},{"id":"T1098.001","name":"Additional Cloud Credentials","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation restricts access to cloud identity management APIs, preventing adversaries in compromised zones from adding unauthorized cloud credentials to accounts in protected cloud environments."},{"id":"T1102.001","name":"Dead Drop Resolver","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection with web filtering can block dead-drop resolver connections by restricting access to social media, paste sites, and other platforms used to host encoded C2 address information."},{"id":"T1102.002","name":"Bidirectional Communication","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network boundary controls can block bidirectional web-service C2 by restricting API-level access to cloud platforms and monitoring for persistent, unusual data exchanges with web services."},{"id":"T1102.003","name":"One-Way Communication","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection can block one-way web-service C2 by restricting outbound connections to web platforms used for command retrieval, disrupting the adversary's ability to push instructions through legitimate services."},{"id":"T1114.003","name":"Email Forwarding Rule","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation protects email infrastructure from unauthorized forwarding-rule creation by restricting access to Exchange/O365 management interfaces from authorized administrative zones only."},{"id":"T1132.001","name":"Standard Encoding","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection with traffic inspection can detect standard-encoding in C2 traversing the perimeter by identifying Base64 or URL-encoded data in protocol fields where plaintext is expected."},{"id":"T1132.002","name":"Non-Standard Encoding","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network boundary inspection can detect non-standard encoding in C2 by performing entropy analysis on traffic crossing the perimeter, identifying custom encoding that deviates from normal protocol data."},{"id":"T1136.002","name":"Domain Account","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation restricts domain account creation by limiting access to Active Directory domain controllers from authorized administrative zones, preventing adversary account creation across boundaries."},{"id":"T1136.003","name":"Cloud Account","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection restricts cloud account creation by enforcing network-level controls on access to cloud IAM APIs, preventing unauthorized account provisioning from compromised network zones."},{"id":"T1204.001","name":"Malicious Link","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection with URL filtering blocks access to malicious link destinations by maintaining categorized URL databases and preventing users from navigating to known phishing and exploitation sites."},{"id":"T1204.002","name":"Malicious File","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Network boundary controls with content filtering can block malicious file downloads by inspecting transferred files at the perimeter and preventing delivery of weaponized documents and executables."},{"id":"T1204.003","name":"Malicious Image","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection can restrict access to container registries, preventing deployment of malicious images by blocking connections to unauthorized registries from production network zones."},{"id":"T1205.001","name":"Port Knocking","tactics":["command-and-control","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Network boundary stateful inspection can defeat port-knocking sequences by requiring established sessions and rejecting the irregular connection patterns characteristic of port-knocking activation attempts."},{"id":"T1218.012","name":"Verclsid","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection can limit verclsid proxy-execution impact by blocking outbound connections from verclsid.exe-launched payloads that attempt to reach C2 infrastructure across the network perimeter."},{"id":"T1218.015","name":"Electron Applications","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Network boundary controls can restrict Electron application network access by filtering outbound connections from Electron-based processes to prevent communication with adversary infrastructure."},{"id":"T1498.001","name":"Direct Network Flood","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection devices—including rate-limiting firewalls and DDoS-scrubbing services—directly mitigate direct network floods by filtering volumetric attack traffic before it saturates internal infrastructure."},{"id":"T1498.002","name":"Reflection Amplification","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Network boundary protection with anti-amplification controls mitigates reflection attacks by blocking spoofed source-address traffic and rate-limiting responses from reflectable services."},{"id":"T1499.001","name":"OS Exhaustion Flood","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection with connection-rate limiting mitigates OS exhaustion floods by throttling excessive inbound connection attempts before they deplete operating-system-level resources on target systems."},{"id":"T1499.002","name":"Service Exhaustion Flood","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Network boundary rate limiting mitigates service exhaustion floods by restricting request rates to protected services, preventing service-level resource depletion from high-volume attacks."},{"id":"T1499.003","name":"Application Exhaustion Flood","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection with application-aware filtering mitigates application exhaustion floods by identifying and throttling request patterns designed to consume excessive application resources."},{"id":"T1499.004","name":"Application or System Exploitation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Network boundary controls with intrusion-prevention capabilities can detect and block exploitation-based DoS by identifying exploit payloads targeting application vulnerabilities to cause service disruption."},{"id":"T1505.004","name":"IIS Components","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection can restrict IIS component access by enforcing web application firewall rules that detect malicious module installation attempts and limiting management-interface access to authorized zones."},{"id":"T1542.004","name":"ROMMONkit","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation isolates network device management interfaces, restricting access to ROM monitor environments and preventing ROMMONkit installation from compromised zones."},{"id":"T1542.005","name":"TFTP Boot","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection restricts TFTP boot manipulation by controlling access to TFTP servers and boot-image repositories, preventing adversaries from substituting malicious boot images."},{"id":"T1552.001","name":"Credentials In Files","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation limits access to file systems containing credentials by restricting cross-zone file access, reducing the attack surface for extracting credentials stored in plaintext files."},{"id":"T1552.004","name":"Private Keys","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection limits access to systems storing private keys by enforcing network-level controls that restrict which zones can reach key-storage locations and SSH/TLS certificate repositories."},{"id":"T1552.005","name":"Cloud Instance Metadata API","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation can restrict access to cloud instance metadata APIs by limiting which network paths can reach the metadata endpoint, preventing credential harvesting from compromised containers or workloads."},{"id":"T1552.007","name":"Container API","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection around container environments restricts access to container APIs that expose credentials, limiting which network zones can query container runtime metadata and secrets."},{"id":"T1557.001","name":"LLMNR/NBT-NS Poisoning and SMB Relay","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation limits LLMNR/NBT-NS poisoning scope by isolating broadcast domains, restricting the network segments within which adversaries can intercept name-resolution queries and relay SMB authentication."},{"id":"T1557.002","name":"ARP Cache Poisoning","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection with segmented VLANs limits ARP poisoning scope by restricting the broadcast domain within which adversaries can inject gratuitous ARP responses and intercept traffic."},{"id":"T1557.003","name":"DHCP Spoofing","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation limits DHCP spoofing impact by isolating DHCP broadcast domains and enforcing DHCP snooping at boundary switches to prevent rogue server responses from reaching protected subnets."},{"id":"T1557.004","name":"Evil Twin","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection with wireless-network controls limits evil twin attacks by enforcing wireless intrusion detection, rogue-AP suppression, and network-access controls that validate legitimate access points."},{"id":"T1559.001","name":"Component Object Model","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation restricts remote COM instantiation by blocking DCOM traffic at zone boundaries, preventing adversaries from executing code through COM interfaces across network segments."},{"id":"T1559.002","name":"Dynamic Data Exchange","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection can limit DDE exploitation impact by restricting outbound connections from Office processes that may establish C2 channels following DDE-based code execution."},{"id":"T1560.001","name":"Archive via Utility","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Network boundary DLP controls can detect archived data being staged for exfiltration by inspecting outbound transfers for compressed and encrypted files created by archiving utilities."},{"id":"T1563.002","name":"RDP Hijacking","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation restricts RDP hijacking by limiting RDP access across zone boundaries, preventing adversaries from connecting to active or disconnected RDP sessions across network segments."},{"id":"T1565.001","name":"Stored Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection restricts access to critical data stores, preventing stored-data manipulation by ensuring that only authorized systems and users in approved zones can modify sensitive data repositories."},{"id":"T1565.003","name":"Runtime Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation limits runtime data manipulation by restricting access to application-processing environments from less-trusted zones, reducing opportunities for adversaries to tamper with data in transit."},{"id":"T1566.001","name":"Spearphishing Attachment","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection at email gateways scans spearphishing attachments, detonates suspicious files in sandboxes, and blocks weaponized content before targeted phishing emails reach internal mailboxes."},{"id":"T1566.002","name":"Spearphishing Link","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Network boundary URL filtering blocks spearphishing link destinations by preventing users from navigating to credential-harvesting pages, exploit-kit landing pages, and other malicious URLs."},{"id":"T1566.003","name":"Spearphishing via Service","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection extends to collaboration-service gateways, filtering malicious content delivered through third-party messaging platforms that may bypass traditional email security controls."},{"id":"T1567.001","name":"Exfiltration to Code Repository","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Network boundary controls can block exfiltration to code repositories by restricting access to Git hosting platforms and monitoring for unusual push operations containing sensitive data."},{"id":"T1567.002","name":"Exfiltration to Cloud Storage","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection with egress filtering can block exfiltration to cloud storage by restricting outbound connections to unauthorized cloud-storage providers and detecting anomalous upload patterns."},{"id":"T1567.003","name":"Exfiltration to Text Storage Sites","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Network boundary controls can block exfiltration to text-storage sites (Pastebin, Ghostbin) by restricting access to paste services and monitoring for data uploads to these platforms."},{"id":"T1567.004","name":"Exfiltration Over Webhook","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection can block exfiltration over webhooks by restricting outbound webhook connections to only authorized integration endpoints and monitoring for unusual webhook data volumes."},{"id":"T1568.002","name":"Domain Generation Algorithms","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network boundary DNS controls can disrupt domain generation algorithms by sinkholing algorithmically generated domains, blocking resolution of DGA-produced names, and alerting on characteristic query patterns."},{"id":"T1573.001","name":"Symmetric Cryptography","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection with TLS inspection can detect symmetric-cryptography C2 by decrypting traffic at the perimeter and analyzing session content for malicious payloads and command structures."},{"id":"T1573.002","name":"Asymmetric Cryptography","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network boundary TLS inspection can detect asymmetric-cryptography C2 by analyzing certificate attributes, identifying self-signed or adversary-controlled certificates, and inspecting decrypted traffic for malicious content."},{"id":"T1590.002","name":"DNS","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection limits DNS reconnaissance by restricting zone-transfer capabilities, implementing split DNS architectures, and minimizing the information exposed through external DNS records."},{"id":"T1598.001","name":"Spearphishing Service","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Network boundary controls at messaging gateways filter reconnaissance spearphishing through third-party services by scanning inbound messages for social-engineering indicators and malicious content."},{"id":"T1598.002","name":"Spearphishing Attachment","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection at email gateways scans reconnaissance spearphishing attachments for tracking mechanisms, information-gathering payloads, and malicious content designed to harvest organizational intelligence."},{"id":"T1598.003","name":"Spearphishing Link","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Network boundary URL filtering blocks reconnaissance spearphishing links by preventing access to credential-harvesting pages, tracking pixels, and information-gathering infrastructure embedded in phishing messages."},{"id":"T1599.001","name":"Network Address Translation Traversal","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection directly addresses NAT traversal by enforcing strict NAT configurations on boundary devices, monitoring for unauthorized translation rules, and preventing traffic bypass through NAT manipulation."},{"id":"T1602.001","name":"SNMP (MIB Dump)","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Network segmentation restricts SNMP access by placing management interfaces in dedicated zones and filtering SNMP traffic at boundaries, preventing unauthorized MIB queries from compromised segments."},{"id":"T1602.002","name":"Network Device Configuration Dump","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Boundary protection restricts network device management access by enforcing out-of-band management networks and filtering management-protocol traffic at zone boundaries to prevent unauthorized configuration extraction."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: iso_27001_2022 A.8.16 added from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR entry 155), which OSA's mapping now takes as its base. 2026-10-03: nist_csf_2 PR.DS-01, PR.DS-02, PR.DS-10 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-011","SP-012","SP-013","SP-015","SP-017","SP-019","SP-020","SP-023","SP-025","SP-026","SP-027","SP-028","SP-029","SP-030","SP-031","SP-034","SP-035","SP-036","SP-037","SP-038","SP-039","SP-040","SP-041","SP-042","SP-046","SP-047","SP-050","SP-051","SP-053","SP-054"]}}