Reference material for identity, physical safeguards, risk, compliance, segmentation, attack recognition, and network hardening.
Network security uses technical and operational controls to protect devices, traffic, identities, and services. The references in this section focus on selecting the appropriate boundary and understanding what each control can—and cannot—do.
| Reference | Use it for |
|---|---|
| AAA and Network Identity Controls | Authentication, authorization, accounting, and least privilege |
| Physical Security for Network Infrastructure | Facilities, racks, cabling, entry controls, and environmental monitoring |
| Deception Technology | Honeypots, honeynets, sinkholes, detection, and isolation |
| Risk, Vulnerabilities, Exploits, and the CIA Triad | Security vocabulary, impact analysis, and control selection |
| Compliance, Audit Evidence, and Data Locality | Technical controls and evidence for requirements and location constraints |
| Network Segmentation for Guest, BYOD, IoT, and OT | Trust zones, least-access policy, and lateral-movement reduction |
| Common Network Attack Classes | Denial of service, spoofing, rogue infrastructure, wireless threats, and social engineering |
| Network Hardening, NAC, and Access Control Lists | Admission, filtering, device hardening, and screened-subnet design |
Effective security is layered. Identity controls determine who is connecting; segmentation and filtering limit where they can go; hardening reduces device exposure; monitoring and records supply evidence; and physical safeguards protect the infrastructure itself.