Network Security
Network security protects computer networks and their traffic from unauthorized access, misuse, and disruption. It combines hardware, software, and policy controls to defend data in transit and the infrastructure that carries it.
itDefensive security and security operations | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic — Network Security
Network security is the collection of controls that decides what may move between systems, what gets inspected on the way, and what happens when the answer is no. Networks are extremely good at moving data. They are less discerning about whether that data has a convincing reason to be there. This is why the doors need locks, signs, logs, and occasionally a very firm bouncer.
The useful picture is not one magnificent firewall standing between civilization and the internet. It is defense in depth: several controls around data in motion and the devices carrying it. A firewall narrows the traffic at a boundary. Segmentation limits where a compromised system can go next. Encryption stops observers on an untrusted path from reading the traffic. Monitoring supplies the awkward but necessary evidence when something still gets through.
The surprise is that a network boundary is not automatically a security boundary. A VLAN, virtual network, or tidy diagram can separate things by name. It contains a breach only when traffic crossing that separation meets an enforcement point with a deliberate policy. A broad allow rule is therefore a small piece of prose with a surprisingly large blast radius.
This is also why zero trust does not mean throwing away firewalls and adopting a slogan. It removes the assumption that internal location proves trust. Access decisions use identity, device posture, and context, while segmentation and monitoring still reduce the harm when one decision is wrong. The perimeter did not vanish; it acquired many relatives.
When something looks suspicious, the rhythm is detect, contain, investigate, eradicate, recover, then learn. Flow records show who talked to whom. Packet capture preserves detail. DNS logs can reveal a hidden channel. None is glamorous, but neither is discovering that the only record of a network incident was a confident recollection from Tuesday.
Read the Intro for the architecture and the reason each layer exists. Use the Slides to keep the trust-zone and control relationships in one view. Keep the Cheatsheet nearby when terms such as stateful inspection, IPsec, IDS, and microsegmentation start arriving in groups. The practice reference and exercise turn the main idea into evidence: an allowed flow, a denied flow, and a policy that can explain both.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final
Supports
- SC (System and Communications Protection) family defining boundary protection, encryption, and network controls
- AC (Access Control) family defining network access, least privilege, and separation of duties
- Defense-in-depth as layered controls at network, transport, and application layers
- SC-7 Boundary Protection requiring managed interfaces and deny-by-default policies
- Segmentation, firewall, IDS/IPS, and access control claims throughout the course
- Quiz answers about deny-by-default, segmentation purpose, and stale firewall rules
- https://csrc.nist.gov/pubs/sp/800/207/final
Supports
- Zero Trust Architecture definition and core tenets
- Network location as insufficient for access decisions
- Per-request verification with identity, device, and context
- Incremental adoption recommendations
- Quiz answers about zero trust versus perimeter security and adoption strategy
- https://www.nist.gov/cyberframework
Supports
- Risk-based framework with govern, identify, protect, detect, respond, and recover functions
- Mapping network security controls to organizational risk outcomes
- Referenced in standards comparison slide and cheatsheet
- https://csrc.nist.gov/pubs/sp/800/94/final
Supports
- IDPS technology types (network-based, wireless, host-based, network behavior analysis)
- IDS versus IPS distinction (passive alert versus inline blocking)
- Signature-based versus anomaly-based detection
- Deployment placement recommendations
- Quiz answer about IDS passive mode
- https://csrc.nist.gov/pubs/sp/800/41/r1/final
Supports
- Firewall types and generations (packet filter, stateful, application-layer)
- Firewall policy design principles and rule management
- Quiz answer about stateful inspection
- https://csrc.nist.gov/pubs/sp/800/215/final
Supports
- Secure enterprise network landscape including cloud and remote access
- Evolution from perimeter-centric to distributed network security
- How traditional approaches adapt when network boundaries dissolve
- https://www.cisa.gov/resources-tools/resources/guidance-and-strategies-protect-network-edge-devices
Supports
- Hardening guidance for firewalls, routers, VPN gateways, and IoT devices
- Network edge as a high-value target requiring specific security attention
- Quiz answer about DNS tunneling detection and TLS inspection risks
- https://www.cisa.gov/zero-trust-maturity-model
Supports
- Maturity model for incremental zero trust adoption
- Pillars covering identity, devices, networks, applications, and data
- Quiz answer about phased zero trust adoption strategy
- https://www.cisecurity.org/controls
Supports
- Prioritized security safeguards organized in implementation groups
- Control 9 (Email and Web Browser Protections)
- Control 12 (Network Infrastructure Management)
- Control 13 (Network Monitoring and Defense)
- Segmentation and firewall rule review claims
- https://csrc.nist.gov/pubs/sp/800/153/final
Supports
- Wireless network security guidelines
- WPA2/WPA3 recommendations and enterprise deployment
- https://www.wi-fi.org/discover-wi-fi/security
Supports
- WPA3 specification overview including SAE handshake
- Forward secrecy and resistance to offline dictionary attacks
- Protected Management Frames requirement
- Quiz answer about WPA3 advantages over WPA2
- https://csrc.nist.gov/pubs/sp/800/77/r1/final
Supports
- IPsec VPN architecture and deployment guidance
- Transport and tunnel mode distinctions
- Site-to-site and remote access VPN claims
- https://www.snort.org/
Supports
- Snort as open-source IDS/IPS maintained by Cisco
- Signature-based detection capabilities
- Quiz answer about IDS alert-only behavior
- https://csrc.nist.gov/glossary/term/defense_in_depth
Supports
- Defense in depth as layered countermeasures achieving security objectives
- Glossary definition
- https://csrc.nist.gov/glossary/term/least_privilege
Supports
- Least privilege as restricting authorizations to those needed for a task
- Glossary definition and access control principle
- https://datatracker.ietf.org/doc/html/rfc2401
Supports
- November 1998 IPsec security architecture milestone in 10-timeline.yaml
- https://csrc.nist.gov/pubs/sp/800/48/final
Supports
- November 2002 wireless network security guidance milestone in 10-timeline.yaml
- https://csrc.nist.gov/pubs/sp/800/41/r1/final
Supports
- September 2009 firewall policy guidance milestone in 10-timeline.yaml
- https://www.icann.org/en/announcements/details/icanns-first-dnssec-key-ceremony-for-the-root-zone-7-6-2010-en
Supports
- July 2010 root-zone DNSSEC deployment milestone in 10-timeline.yaml
- https://csrc.nist.gov/pubs/sp/800/153/final
Supports
- February 2012 WLAN security guidance milestone in 10-timeline.yaml
- https://www.nist.gov/news-events/news/2014/02/nist-releases-cybersecurity-framework-version-10
Supports
- February 2014 CSF 1.0 milestone in 10-timeline.yaml
- https://csrc.nist.gov/news/2020/zero-trust-architecture-nist-publishes-sp-800-207
Supports
- August 2020 zero trust architecture milestone in 10-timeline.yaml
- https://www.nist.gov/news-events/news/2024/02/nist-releases-version-20-landmark-cybersecurity-framework
Supports
- February 2024 CSF 2.0 milestone in 10-timeline.yaml
- https://www.paloaltonetworks.com/network-security/next-generation-firewall
Supports
- Palo Alto Networks NGFW landscape entry
- https://www.fortinet.com/products/next-generation-firewall
Supports
- Fortinet FortiGate landscape entry
- https://www.cisco.com/site/us/en/products/security/firewalls/index.html
Supports
- Cisco Secure Firewall landscape entry
- https://www.checkpoint.com/quantum/next-generation-firewall/
Supports
- Check Point Quantum landscape entry
- https://www.cloudflare.com/products/magic-firewall/
Supports
- Cloudflare Magic Firewall landscape entry
