Sekit CSF · Familia
Network Security
24 controles en 8 temas, cada uno visto a través de las lentes de política, proceso y técnica.
Política
RCF-0178Email securitysin mapeos aúnFormal controls are required to protect against phishing, spoofing and malicious email contentRCF-0172Firewall managementsin mapeos aúnFormal policies govern which network traffic is permitted and how firewall rules are created and reviewedRCF-0169Network segmentationsin mapeos aúnThe company formally divides its network into zones to limit the spread of threats between systemsRCF-0175Secure DNSsin mapeos aúnThe company formally requires that domain name resolution is protected against manipulation and abuseRCF-0181TLS termination/hardeningsin mapeos aúnThe company formally requires that encrypted communications use strong protocols and current cipher suitesRCF-0187VPN managementsin mapeos aúnRemote network access through virtual private networks is formally governed and restricted to approved users and devicesRCF-0190Wireless securitysin mapeos aúnThe company formally defines security requirements for all wireless networks it operates or permitsRCF-0184Zero Trust network accesssin mapeos aúnThe company formally adopts the principle that no user or device is trusted by default regardless of network location
Proceso
RCF-0179Email securitysin mapeos aúnEmail security controls are consistently maintained and suspicious emails are investigated and reportedRCF-0173Firewall managementsin mapeos aúnFirewall rules are consistently reviewed and unused or overly permissive rules are removedRCF-0170Network segmentationsin mapeos aúnNetwork zones are consistently maintained and traffic between them is controlled and reviewedRCF-0176Secure DNSsin mapeos aúnDNS configurations are consistently reviewed and DNS traffic is monitored for malicious activityRCF-0182TLS termination/hardeningsin mapeos aúnTLS configurations are consistently reviewed and weak protocols or ciphers are disabledRCF-0188VPN managementsin mapeos aúnVPN access is consistently provisioned, reviewed and removed when no longer requiredRCF-0191Wireless securitysin mapeos aúnWireless networks are consistently configured to security standards and unauthorised access points are identifiedRCF-0185Zero Trust network accesssin mapeos aúnZero trust access principles are consistently applied and all access requests are verified before being granted
Técnica
RCF-0180Email securitysin mapeos aúnTechnical tools enforce SPF, DKIM, DMARC and scan incoming email for malicious links and attachmentsRCF-0174Firewall managementsin mapeos aúnTechnical tools manage firewall rule sets and alert on changes or rules that conflict with security policyRCF-0171Network segmentationsin mapeos aúnTechnical controls enforce network boundaries and restrict traffic between zones based on policyRCF-0177Secure DNSsin mapeos aúnTechnical controls implement DNS filtering, DNSSEC and monitoring to detect and block malicious domainsRCF-0183TLS termination/hardeningsin mapeos aúnTechnical controls enforce TLS version and cipher standards across all services and flag non-compliant endpointsRCF-0189VPN managementsin mapeos aúnTechnical controls enforce authentication, encryption and access policy for all VPN connectionsRCF-0192Wireless securitysin mapeos aúnTechnical controls enforce wireless encryption, segment guest networks and detect rogue access pointsRCF-0186Zero Trust network accesssin mapeos aúnTechnical controls enforce continuous verification of identity and device health before granting network access
Pregúntale a Sekura: «¿Qué evidencia demuestra Network Security?»
Conecta tu IA · MCP gratis
https://staging.sekit.ai/api/mcp/crosswalk- En Claude o ChatGPT, añade un conector personalizado y pega esta URL.
- Inicia sesión con tu correo para terminar. Gratis, de solo lectura, sin necesidad de organización.