Lateral Movement
What is Lateral Movement?
Techniques used by attackers after gaining initial access to move through a network to find and access higher-value targets. Lateral movement involves using compromised credentials and exploiting trust relationships between systems.
Terms that appear alongside lateral movement
Each of these is named in at least one of the same controls as lateral movement. The number is how many controls name both.
- privilege escalation 4 shared controls
- ransomware 3 shared controls
- authentication 3 shared controls
- reconnaissance 3 shared controls
- data exfiltration 3 shared controls
- chain of custody 3 shared controls
- network monitoring 2 shared controls
- audit 2 shared controls
Frameworks that govern lateral movement
What the standards actually require on lateral movement
Requirements naming lateral movement across 6 standards, quoted from the control text.
Apply the 14 Enterprise Tactics representing the adversary tactical goals during cyberattack phases (kill chain). TA0043 Reconnaissance - gathering information for planning future operations.
MITRE-ATTACK-Tactics-14-Enterprise-Kill-Chain-Reconnaissance-Initial-Access-Discovery-Lateral-Movement-Impact · MITRE ATT&CK 14 Enterprise Tactics + Reconnaissance + Initial Access + Discovery + Lateral Movement + Impact →X.805 Clause 8 defines 5 Threat Categories that the X.805 Security Architecture is designed to mitigate + provides a Threat-Dimension Countermeasure Matrix linking each threat to specific Dimensions.
X805-Threats-Destruction-Corruption-Removal-Disclosure-Interruption-72Cell-Matrix-Application · ITU-T X.805 5 Threat Categories - Destruction + Corruption + Removal + Disclosure + Interruption + Threat-Dimension Countermeasure Matrix + 72-Cell Matrix Application + STRIDE + MITRE ATT and CK + Network Modular Risk Assessment →Segment IT and operational technology networks to limit lateral movement and contain potential compromises.
AWWA-3.1 · Network Segmentation →Implement network segmentation between IT and OT networks. Use firewalls and access controls to limit lateral movement.
CPG-8.A · Network Segmentation →FAA AC 120-76D (latest revision) addresses Electronic Flight Bag (EFB) operational authorisation including cybersecurity considerations: (a) EFB classification (Class 1 / Class 2 / Class 3 - portable + installed + integrated) with different cybersecurity basel...
FAA-CSA-EFB · Electronic Flight Bag (EFB) Operational Authorisation Cybersecurity →HKMA C-RAF iCAST (Intelligence-led Cyber Attack Simulation Testing) - mandatory for HIGH inherent risk AIs + optional for medium tier + modeled on UK CBEST + ECB TIBER-EU (verified separately in this corpus) + intelligence-led red team testing methodology.
HKMA-CRAF-iCAST-RedTeam-PurpleTeam-IntelLed · HKMA C-RAF iCAST (Intelligence-Led Cyber Attack Simulation Testing) for HIGH Inherent Risk AIs →Questions people ask about lateral movement
What is Lateral Movement?
Why is Lateral Movement important for compliance?
Which compliance frameworks address Lateral Movement?
Where can I learn more about Lateral Movement?
See how Lateral Movement applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.