Skip to content
NET9 finding classes

Network

What can be reached, and from where?

The Network domain covers reachability: which services are exposed, to which networks, and what sits between an untrusted packet and a sensitive system. Most Tier 1 findings are network findings in disguise — a vulnerable service that nothing can route to is a very different problem from the same service on a public IP.

What this domain covers

  • Internet and partner-network service exposure
  • Firewall, security group, and network ACL configuration
  • Segmentation between trust zones and regulated environments
  • Ingress and egress filtering
  • Network telemetry, flow logging, and intrusion detection coverage

Distribution across tiers

Tier 1 · Critical3 · 24–72 hours
Tier 2 · Regulatory3 · 30 days
Tier 3 · Best Practices3 · 90 days

Typically owned by Network engineering / cloud platform.

Tier 1 · CriticalCould an external attacker use this to gain access, escalate privilege, or take data — today, without an insider and without a chain of unlikely events?
Tier 2 · RegulatoryWould a named auditor, regulator, or contractual counterparty record this as a deficiency?
Tier 3 · Best PracticesDoes fixing this reduce the number or severity of future Tier 1 and Tier 2 findings?

Other domains