← NIST CSF 2.0 · PROTECT — Technology Infrastructure Resilience

PR.IR-01 — Networks and environments are protected from unauthorised logical access

high network-securitysegregation

Requirement

Networks and environments are protected from unauthorised logical access and usage.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
networkenvironment
Required element 2 — any one of
firewallsecurity groupsegmentisolat…restrictsegmentation
Supporting terms — specificity signals
vpcprivate subnetzero trustbastionno public ingressdeny by defaultwaf

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
ISO 27001 A.8.22 Segregation of networks network-security segregation
PCI DSS 4.0.1 1.3 Restrict network access to and from the cardholder data environment network-security segregation
SOC 2 CC6.6 Boundary protection network-security
ISO 27001 A.5.3 Segregation of duties segregation
ISO 27001 A.8.21 Security of network services network-security
ISO 27001 A.8.31 Separation of development, test and production environments segregation
PCI DSS 4.0.1 1.2 Network security control configuration and review network-security
PCI DSS 4.0.1 1.4 Controls between trusted and untrusted networks network-security