The cybersecurity architecture enables the isolation of compromised assets
Context and Guidance: This practice expands on the implementation of architectural tactics such as network segmentation (ARCHITECTURE-2a) and restricting network to authorised devices (ARCHITECTURE-2k). The cybersecurity architecture may include monitoring that enables the organisation to detect if an asset is compromised and isolate it on a logically separate network. This could enable incident responders to perform analysis on the system in a safe environment, while not impacting other production networks.
Related Practices • Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: ARCHITECTURE-2b, ARCHITECTURE-2d, ARCHITECTURE-2h, ARCHITECTURE-2i, ARCHITECTURE-2j, ARCHITECTURE-2l.