• Access Rights & Permissions Matrix
    • Data Breach Notification Log
    • Data Classification Register
    • Data Loss Prevention (DLP) Incident Log
    • Document Retention & Disposal Tracker
    • Security KPI Dashboard
    • Asymmetric-Key Cryptography
    • Combined Security Model: Digital Signature + Digital Envelope
    • Database Encryption Techniques (API, Plug-in, TDE)
    • Diffie-Hellman Key Exchange
    • Digital Envelope
    • Digital Signature
    • Hash Function
    • Homomorphic Encryption
    • Hybrid Cryptography
    • PKI (Public Key Infrastructure)
    • Post-Quantum Cryptography (PQC)
    • Quantum Security
    • RSA Encryption
    • Sign-then-Encrypt
    • Symmetric-Key Cryptography
    • CIA Triad
    • Endpoint Security
    • Systematic Server Defense Strategy
    • DDoS Attack Mitigation Plan Tracker
    • IP Whitelist–Blacklist Tracker
    • Network Access Control Log
    • Network Device Inventory
    • Network Security Risk Mitigation
    • Network Traffic Monitoring Dashboard
    • DDoS (Distributed Denial of Service)
    • DRDoS (Distributed Reflective Denial of Service)
    • Network Separation & Integration
    • SASE (Secure Access Service Edge)
    • SDP (Software Defined Perimeter)
    • Spoofing
    • Zero Trust
    • IPSec
    • OSI 7-Layer Security
    • OSI 7-Layer Security Threats
    • TLS (Transport Layer Security)
    • Cloud Access Control Matrix
    • Cloud Asset Inventory Tracker
    • Cloud Backup & Recovery Testing Tracker
    • Cloud Incident Response Log
    • Cloud Security Configuration Baseline
    • CASB (Cloud Access Security Broker)
    • CNAPP (Cloud Native Application Protection Platform)
    • The Two Pillars of Cloud Security (CSPM and CWPP)
    • DSPM (Data Security Posture Management)
    • Integrated Cloud-Native Security Architecture
    • Shadow IT
    • Kubernetes Security
    • Amdahl's Law
    • Patch & Update Tracker
    • Secure Coding Checklist
    • Secure Mobile App Testing Tracker
    • Security Misconfiguration Log
    • Static Code Analysis Log
    • Web Application Vulnerability Tracker
    • Application Threat Modeling
    • CSRF (Cross-Site Request Forgery)
    • SQL Injection
    • XSS (Cross-Site Scripting)
    • API Security (OWASP API Top 10 and BOLA)
    • Code Security (SAST, DAST, and Secure Coding)
    • DevSecOps Pipeline
    • DevSecOps
    • Software Supply Chain Security (SBOM and SLSA)
    • Acceptable Use of Assets Policy
    • Password Policy
    • Backup and Recovery Policy
    • Compliance Management
    • Disposal and Destruction Policy
    • Information Classification Policy
    • Information Transfer Policy
    • ISMS Policy
    • COBIT-Based Security Governance
    • ISMS-P
    • ISO 27001
    • Privacy Impact Assessment (PIA)
    • Korea's Data 3 Acts
    • Differential Privacy
    • EU AI Act
    • 5 Pseudonymization Techniques
    • CSAP Tiered Certification
    • Incident Management Policy
    • Incident Management Process
    • Intern Incident Report
    • Major Incident Report Template
    • Structural Damage Incident Report
    • Workplace Violence Report
    • The Core of Endpoint Visibility, EDR
    • The Integrated Control Tower for Threat Detection and Analysis, SIEM
    • Digital Forensics
    • Known Error (KE) Record Template
    • Major Problem Report Template
    • Problem Management Process
    • Problem Record Template
    • DR Approach Document
    • DR Asset Register
    • DR Closure Report
    • DR Communications Plan
    • DR Plan Template
    • MAC vs. DAC vs. RBAC: Access Control Models Compared
    • Access Control
    • Authentication vs. Authorization
    • FIDO (Fast IDentity Online)
    • Identity Provider (IdP)
    • JWT (JSON Web Token)
    • Kerberos
    • OAuth 2.0
    • OAuth 2.0 and OIDC
    • OpenID Connect (OIDC)
    • Passkey
    • SAML (Security Assertion Markup Language)
    • Single Sign-On (SSO)
    • Active Directory (AD)
    • LDAP (Lightweight Directory Access Protocol)
    • Systematic Classification of Attack Techniques
    • Penetration Testing Methodology
    • OSINT (Open Source Intelligence)
    • OSSTMM (Open Source Security Testing Methodology Manual)
    • PTES (Penetration Testing Execution Standard)
    • RAV (Risk Assessment Value)
    • Fuzzing
    • CTF Categories
    • Red Teaming
    • AI System Security
    • Deepfake
    • LLM Security (OWASP Top 10 for LLM)
    • OT/ICS Security and the Purdue Model
    • Blockchain
    • GitHub
  • to navigate
  • to select
  • to close
    • Home
    • Network Security
    On this page
    hub

    Network Security

    Templates and trackers for perimeter defense, access control, device inventory, and traffic monitoring across the network.

    bolt

    DDoS Attack Mitigation Plan Tracker

    A living record of DDoS defense readiness — attack vectors covered, mitigation controls, and drill history for the network perimeter.

    rule

    IP Whitelist–Blacklist Tracker

    A single source of truth for every allowed and blocked IP address, subnet, and the business justification behind each entry.

    fact_check

    Network Access Control Log

    A chronological record of who or what connected to the network, from where, and whether that access was authorized.

    router

    Network Device Inventory

    An authoritative catalog of every router, switch, firewall, and access point, its configuration state, and patch status.

    security

    Network Security Risk Mitigation

    A prioritized register of network-level risks, their likelihood and impact, and the mitigation plan and owner for each.

    monitoring

    Network Traffic Monitoring Dashboard

    A live and historical view of network flow volume, protocol mix, and anomaly alerts used to spot threats in near real time.

    bolt

    DDoS (Distributed Denial of Service)

    A distributed attack that mobilizes botnets to exhaust a target's resources and deny service to legitimate users.

    repeat

    DRDoS (Distributed Reflective Denial of Service)

    A denial-of-service attack that spoofs the victim's IP address to trick reflector servers into flooding the victim with amplified responses.

    call_split

    Network Separation & Integration

    The set of technologies that isolate the internal business network from the internet while enabling safe, controlled data transfer between …

    cloud_sync

    SASE (Secure Access Service Edge)

    A cloud-native architecture that converges networking functions such as SD-WAN with security services such as ZTNA and CASB on a single …

    visibility_off

    SDP (Software Defined Perimeter)

    A security architecture that cloaks infrastructure from the outside world until device authentication and user trust are verified.

    badge

    Spoofing

    An attack that forges network identifiers such as IP, MAC, or DNS to impersonate a trusted party and hijack a trust relationship.

    verified_user

    Zero Trust

    A security model built on 'never trust, always verify' that removes the internal/external distinction and continuously validates every …

    vpn_lock

    IPSec

    A protocol suite that establishes an encrypted, authenticated security channel at the network layer (L3) for data carried over IP networks.

    layers

    OSI 7-Layer Security

    A framework that analyzes the security threats specific to each OSI-model layer and applies matching security technologies and solutions at …

    report_problem

    OSI 7-Layer Security Threats

    A layer-by-layer inventory of the security vulnerabilities unique to each OSI layer and the technical defenses that counter them.

    https

    TLS (Transport Layer Security)

    The transport-layer security protocol (RFC 8446) that establishes an encrypted channel between client and server to guarantee …


    © 2026 Cybersecurity Knowledge Base. Built with Lotus Docs