Frameworks / ASD Strategies to Mitigate Cyber Security Incidents / ASD37-25 ASD Strategies to Mitigate Cyber Security Incidents
Limiting the Extent of Cyber Security Incidents
ASD Strategies to Mitigate Cyber Security Incidents ASD37-25: Software firewall - inbound (Very Good) Software-based application firewall, blocking incoming network traffic that is malicious or unauthorised.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 119 controls across 78 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
SC-7 Boundary Protection SC-7(12) Boundary Protection | Host-based Protection (SC-7(12)) SC-7(5) Deny by Default Allow by Exception SC-7 Boundary Protection SC-7(12) Boundary Protection | Host-based Protection (SC-7(12)) SC-7(5) Deny by Default Allow by Exception 1.3.1 1.3.1 Inbound CDE traffic restricted 1.4.2 1.4.2 Restricting traffic entering trusted networks from outside 1.5.1 1.5.1 Security controls on dual-connected devices NS-1 Establish network segmentation boundaries NS-3 Deploy firewall at the edge of enterprise network CIS-4.4 Implement and Manage a Firewall on Servers CIS-4.5 Implement and Manage a Firewall on End-User Devices CPG-1.D Revoking Credentials for Departing Employees CPG-8.A Network Segmentation 8.1 User end point devices 8.20 Networks security 8.1 User endpoint devices 8.20 Networks security 27011-6.3 Awareness and Training 27011-8.2 Network security and segregation 03.13.01 Boundary Protection 03.13.06 Network Communications - Deny by Default - Allow by Exception ANSSI-HYG-17 Enable and Configure the Local Firewall on Workstations API1164-13 Business Continuity and Recovery SEC05-BP02 Control traffic flow within your network layers AWWA-3.1 Network Segmentation CAT-D3-1 Preventative controls FFIEC-06 Network security and segmentation GLBA-Subordinate-Rules-Operationalisation GLBA Operationalisation through FTC Safeguards Rule, Privacy Rule, SEC Reg S-P and Banking-Agency Guidelines HKMA-SPM-TM-Technology-TM-G-1-CRAF-Coord HKMA SPM Technology Management Modules (TM-G-1 to TM-G-4, TM-E-1) + Coordination with C-RAF IACS-UR-E26-Protect-NetworkSegmentation-Zones-Conduits-Boundary IACS UR E26 Protect Goal - Network Segmentation + Zones + Conduits + Boundary Defence + Data Diodes IEC62443-13 Network security monitoring IEEE1686-Section5.2-5.3-AuditLog-Retention-Export-Monitoring IEEE 1686 Section 5.2 + 5.3 - Audit Trail Records + Retention + Export + Supervisory Monitoring and Control + Network Security Monitoring ISO28001-PS-01 Facility Security 27010-13.1 Communications Security ISO27019-13 Network security monitoring ISO27043-27 Network security management ISO21434-27 Network security management LAOS-CC-Network-Security-Information-Security-Obligations-Article-21-Service-Provider-Duties Laos Cybercrime Network Security + Information Security Obligations + Article 21 + Service Provider Duties MTCS-Incident-Business-Continuity-CSC-Data-Protection-72-Hour-Notification-BCP-DR-PDPA MTCS Incident + Business Continuity + CSC Data Protection + 72-Hour Notification + BCP + DR + PDPA MAS-TRM-Project-SDLC-Service-Management-Chapters-4-5-6-IT-Project-Software-Lifecycle-Change-ITIL MAS TRM Project + SDLC + Service Management + Chapters 4-6 + IT Project + Software Lifecycle + ITIL MMCL-5 Content Moderation, Removal Requests, and Lawful Access NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010) NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage NISTPF-5 Protect-P Access Control (PR.AC-P) NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring NISTSP144-2 Cloud Architecture, Service Selection, and Tenant Isolation NISTSP145-6 Deployment Model Classification (Private, Community, Public, Hybrid) NISTSP146-4 IaaS Operational Recommendations and Workload Hardening NISTSP61-4 Detection and Analysis: Sources, Triage, Categorisation, Prioritisation NISTSP63R4-5 Federation: Assertions, Trust Agreements, RP Validation, Pseudonymous Identifiers NISTSP88-8 Cloud-Resident Data, Hosted Storage, and Scope Boundaries NISTSP92-3 Log Infrastructure: Architecture, Centralisation, Transport Security, SIEM Governance NZISM-5 Network Security, System Hardening, and Application Security ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management OMANCS-5 Network, Endpoint, System Development, and Configuration Security OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns PCI-P2PE-06 Network security and segmentation PCI-PIN-06 Network security and segmentation PCI-SSF-06 Network security and segmentation PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements PTESPHASE-4 Vulnerability Analysis SHAREASSESS-4 Vulnerability Management, Patching, Application Security SUPCHAIN-3 Dependency Verification and SBOM SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary IM8-SEC.3 Network Security ISMSP-AC-04 Network Access Control TSAPIPE-2 OT/IT Network Segmentation and Access Control CPSC-CS.1 Network Security for Connected Products USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Limiting the Extent of Cyber Security Incidents You are reading one control. How much of ASD Strategies to Mitigate Cyber Security Incidents have you already done? ASD Strategies to Mitigate Cyber Security Incidents ASD37-25 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ASD Strategies to Mitigate Cyber Security Incidents your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 32 of 37 ASD Strategies to Mitigate Cyber Security Incidents controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 119 it maps to, and the evidence behind each claim, over MCP and REST.