# SP-016 DMZ Module

Status: published. Release 26.02. Modified 2026-02-06. Licence: CC BY-SA 4.0.

Scope: Security architecture for designing and operating a demilitarized zone (DMZ) network segment. Covers multi-tier firewall topologies, bastion host hardening, traffic inspection, DNS security, intrusion detection, audit logging, and the controlled exposure of services to untrusted networks.
Use when: Any organisation with a secure computing environment that connects to untrusted networks. Organisations hosting internet-facing services (web applications, email, VPN, APIs).
Not when: Single-user environments such as home users without server infrastructure.

## Controls (31, NIST SP 800-53 ids)
- Critical (6): AC-04, AU-02, AU-06, CM-07, RA-05, SI-04
- Important (12): AC-06, AU-03, AU-05, AU-08, AU-09, CA-03, SC-05, SC-20, SC-22, SI-03, SI-05, SI-07
- Standard (13): AC-07, AC-12, AU-04, AU-07, AU-10, AU-11, CA-04, CA-05, SC-10, SC-21, SC-23, SI-06, SI-08
- Withdrawn from SP 800-53 by NIST: CA-04 (now in CA-02)

## What each critical control mitigates (6)
- AC-04 Information Flow Enforcement: T-DZ-003, T-DZ-007
- AU-02 Event Logging: T-DZ-006
- AU-06 Audit Record Review, Analysis, and Reporting: T-DZ-003, T-DZ-005, T-DZ-006, T-DZ-007
- CM-07 Least Functionality: T-DZ-002, T-DZ-010
- RA-05 Vulnerability Monitoring and Scanning: T-DZ-002, T-DZ-010
- SI-04 System Monitoring: T-DZ-001, T-DZ-003, T-DZ-004, T-DZ-010

## Threats and the controls that mitigate them (10)
- T-DZ-001 Denial of Service (Volumetric and Application-Layer): SC-05, SC-10, SI-04
- T-DZ-002 Exploitation of Internet-Facing Service Vulnerabilities: CM-07, RA-05, SI-07, SI-06
- T-DZ-003 Lateral Movement from Compromised DMZ Host: AC-04, AC-06, SI-04, AU-06
- T-DZ-004 Malware Delivery via Web or Email Through DMZ: SI-03, SI-04, SI-08
- T-DZ-005 DNS Cache Poisoning and DNS Tunnelling: SC-20, SC-21, SC-22, AU-06
- T-DZ-006 Brute-Force and Credential Stuffing Attacks: AC-07, AC-12, AU-02, AU-06
- T-DZ-007 Firewall Rule Misconfiguration Allowing Bypass: AC-04, CA-04, CA-05, AU-06
- T-DZ-008 Session Hijacking on DMZ-Hosted Services: SC-23, SC-10, AC-12
- T-DZ-009 Audit Log Tampering by Compromised DMZ Host: AU-09, AU-05, AU-04
- T-DZ-010 Zero-Day Exploitation of Unpatched DMZ Services: SI-05, RA-05, SI-04, CM-07

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-016/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-016/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 24 KB: /api/v1/patterns/SP-016
- Page for people: /patterns/sp-016/
- Related: SP-017 Secure Network Zone Module; SP-013 Data Security Pattern; SP-025 Advanced Monitoring and Detection

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
