# What is Network Security?

> Network security is the discipline of protecting network communications, infrastructure, services, and connected resources against unauthorized access, misuse, disruption, and manipulation while preserving required availability.

- Canonical URL: https://yellowcube.eu/glossary/network-security/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It combines architecture, configuration, identity-aware access, segmentation, traffic control, cryptographic protection, monitoring, maintenance, and response across physical, virtual, cloud, wireless, remote, and third-party network paths.

Effective design begins with inventories, trust relationships, required data flows, and the consequences of failure. Controls are then placed at useful boundaries and endpoints, with policy based on risk rather than an assumption that an internal location is trustworthy. Operations must maintain devices and rules, observe relevant traffic and events, investigate changes, and recover essential connectivity safely.

### Key points

- **Architecture:** Reduce unnecessary reachability, separate environments with different risk or operational needs, protect management planes, and remove single points of failure where resilience requires it.
- **Preventive controls:** Use authentication, least-privilege policy, firewalls, secure configuration, encryption, admission controls, and routing or name-service protections according to the threat and data path.
- **Detection and response:** Collect proportionate telemetry, baseline expected communication, monitor policy enforcement, investigate anomalies, and rehearse containment and restoration without disrupting critical services.
- **Important limitation:** Network security cannot make a vulnerable application, compromised endpoint, unsafe identity process, or malicious authorized action trustworthy. Encryption can protect traffic while also limiting intermediary visibility, so controls must be coordinated across layers.

### Related terms

[Firewall](<https://yellowcube.eu/glossary/firewall/>) · [Network segmentation](<https://yellowcube.eu/glossary/network-segmentation/>) · [Network access control (NAC)](<https://yellowcube.eu/glossary/network-access-control/>) · [Network monitoring](<https://yellowcube.eu/glossary/network-monitoring/>) · [Zero trust architecture (ZTA)](<https://yellowcube.eu/glossary/zero-trust-architecture/>) · [Border Gateway Protocol (BGP)](<https://yellowcube.eu/glossary/border-gateway-protocol/>) · [Branch networking](<https://yellowcube.eu/glossary/branch-networking/>)

### Sources

[NIST SP 800-215: Guide to a Secure Enterprise Network Landscape](https://csrc.nist.gov/pubs/sp/800/215/final) · [NIST SP 800-53 Rev. 5: Security and Privacy Controls](https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final) · [NIST SP 800-207: Zero Trust Architecture](https://csrc.nist.gov/pubs/sp/800/207/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

