Frameworks / ASD Strategies to Mitigate Cyber Security Incidents / ASD37-22 ASD Strategies to Mitigate Cyber Security Incidents
Limiting the Extent of Cyber Security Incidents
ASD Strategies to Mitigate Cyber Security Incidents ASD37-22: Network segmentation (Excellent) Network segmentation and segregation to limit the impact of an intrusion. Deny traffic between computers unless required.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 146 controls across 81 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ANSSI-HYG-07 Authorise Network Connection Only for Managed Equipment ANSSI-HYG-19 Segment the Network and Partition the Zones ANSSI-HYG-23 Partition Internet Facing Services from the Rest of the Information System ANSSI-HYG-25 Secure Dedicated Network Interconnections with Partners ANSSI-HYG-28 Use a Dedicated and Partitioned Network for Administration C5-COS-02 Security requirements for connections in the Cloud Service Provider's network C5-COS-03 Monitoring of connections in the Cloud Service Provider's network C5-COS-04 Cross-network access C5-COS-06 Segregation of data traffic in jointly used network environments C5-OPS-24 Separation of Datasets in the Cloud Infrastructure 1.3.1 1.3.1 Inbound CDE traffic restricted 1.3.2 1.3.2 Outbound CDE traffic restricted 1.4.1 1.4.1 NSCs between trusted and untrusted networks 1.4.4 1.4.4 Cardholder data stores not reachable from untrusted networks 11.4.5 11.4.5 Annual segmentation penetration testing CIS-12.2 Establish and Maintain a Secure Network Architecture CIS-13.4 Perform Traffic Filtering Between Network Segments CIS-3.12 Segment Data Processing and Storage Based on Sensitivity CIS-4.5 Implement and Manage a Firewall on End-User Devices AC-4 Information Flow Enforcement AC-4(21) Physical or Logical Separation of Information Flows SC-7 Boundary Protection SC-7(5) Deny by Default Allow by Exception AC-4 Information Flow Enforcement AC-4(21) Physical or Logical Separation of Information Flows SC-7 Boundary Protection SC-7(5) Deny by Default Allow by Exception ASBv3-GS-2 Define and implement enterprise segmentation/separation of duties strategy NS-1 Establish network segmentation boundaries NS-2 Secure cloud services with network controls 03.01.03 Information Flow Enforcement 03.13.01 Boundary Protection 03.13.06 Network Communications - Deny by Default - Allow by Exception CE-FW.7 Restrict Firewall Administrative Interface from the Internet CE-SCOPE.1 Scope Definition CE-SU.4 Remove Out-of-Support Software CPG-1.D Revoking Credentials for Departing Employees CPG-8.A Network Segmentation 8.22 Segregation of networks 8.3 Information access restriction 8.22 Segregation of networks 8.3 Information access restriction 27011-6.3 Awareness and Training 27011-8.2 Network security and segregation SOC2-CC6.1 CC6.1 Logical access security over protected information assets SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary API1164-13 Business Continuity and Recovery AWWA-3.1 Network Segmentation CAT-D3-1 Preventative controls FFIEC-06 Network security and segmentation GLBA-Subordinate-Rules-Operationalisation GLBA Operationalisation through FTC Safeguards Rule, Privacy Rule, SEC Reg S-P and Banking-Agency Guidelines HKMA-SPM-TM-Technology-TM-G-1-CRAF-Coord HKMA SPM Technology Management Modules (TM-G-1 to TM-G-4, TM-E-1) + Coordination with C-RAF IACS-UR-E26-Protect-NetworkSegmentation-Zones-Conduits-Boundary IACS UR E26 Protect Goal - Network Segmentation + Zones + Conduits + Boundary Defence + Data Diodes IEC62443-13 Network security monitoring IEEE1686-Section5.2-5.3-AuditLog-Retention-Export-Monitoring IEEE 1686 Section 5.2 + 5.3 - Audit Trail Records + Retention + Export + Supervisory Monitoring and Control + Network Security Monitoring ISO28001-PS-01 Facility Security 27010-13.1 Communications Security ISO27019-13 Network security monitoring ISO27043-27 Network security management ISO21434-27 Network security management LAOS-CC-Network-Security-Information-Security-Obligations-Article-21-Service-Provider-Duties Laos Cybercrime Network Security + Information Security Obligations + Article 21 + Service Provider Duties MTCS-Incident-Business-Continuity-CSC-Data-Protection-72-Hour-Notification-BCP-DR-PDPA MTCS Incident + Business Continuity + CSC Data Protection + 72-Hour Notification + BCP + DR + PDPA MAS-TRM-Project-SDLC-Service-Management-Chapters-4-5-6-IT-Project-Software-Lifecycle-Change-ITIL MAS TRM Project + SDLC + Service Management + Chapters 4-6 + IT Project + Software Lifecycle + ITIL MMCL-5 Content Moderation, Removal Requests, and Lawful Access NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010) NISTPF-5 Protect-P Access Control (PR.AC-P) NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring NISTSP144-2 Cloud Architecture, Service Selection, and Tenant Isolation NISTSP145-6 Deployment Model Classification (Private, Community, Public, Hybrid) NISTSP146-4 IaaS Operational Recommendations and Workload Hardening NISTSP61-4 Detection and Analysis: Sources, Triage, Categorisation, Prioritisation NISTSP63R4-5 Federation: Assertions, Trust Agreements, RP Validation, Pseudonymous Identifiers NISTSP88-8 Cloud-Resident Data, Hosted Storage, and Scope Boundaries NISTSP92-3 Log Infrastructure: Architecture, Centralisation, Transport Security, SIEM Governance NZISM-5 Network Security, System Hardening, and Application Security ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management OMANCS-5 Network, Endpoint, System Development, and Configuration Security OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns PCI-P2PE-06 Network security and segmentation PCI-PIN-06 Network security and segmentation PCI-SSF-06 Network security and segmentation PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements PTESPHASE-4 Vulnerability Analysis SHAREASSESS-4 Vulnerability Management, Patching, Application Security SUPCHAIN-3 Dependency Verification and SBOM IM8-SEC.3 Network Security ISMSP-AC-04 Network Access Control TSAPIPE-2 OT/IT Network Segmentation and Access Control CPSC-CS.1 Network Security for Connected Products USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Limiting the Extent of Cyber Security Incidents You are reading one control. How much of ASD Strategies to Mitigate Cyber Security Incidents have you already done? ASD Strategies to Mitigate Cyber Security Incidents ASD37-22 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ASD Strategies to Mitigate Cyber Security Incidents your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 32 of 37 ASD Strategies to Mitigate Cyber Security Incidents controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 146 it maps to, and the evidence behind each claim, over MCP and REST.