diff --git a/controls/core/network/COR.NET.001_restrict_public_access_on_your_infrastructure.md b/controls/core/network/COR.NET.001_restrict_public_access_on_your_infrastructure.md
new file mode 100644
index 000000000..970eabe89
--- /dev/null
+++ b/controls/core/network/COR.NET.001_restrict_public_access_on_your_infrastructure.md
@@ -0,0 +1,70 @@
+---
+id: "COR.NET.001"
+category: "core/network"
+revision-version: 1
+revision-date: "2024-01-12"
+estimate-time: "30m"
+necessity: "mandatory"
+frameworks:
+ - name: "soc2"
+ sections: ["CC6.1", "CC6.6", "CC6.7"]
+---
+
+# Restrict public access on your infrastructure
+
+## Purpose
+
+Public access to your company's infrastructure is a serious security risk. By
+configuring your cloud provider to restrict public access, you can reduce the
+risk of unauthorized access to your sensitive data and systems.
+
+## Implementation
+
+- Ensure your cloud storage buckets are private (it should be the case by
+ default)
+ 1. **Go to the Google Cloud Console,** navigate to **Cloud Storage**.
+ 2. In **Permissions**, enable **Uniform Bucket-Level Access** to enforce
+ bucket-level permissions (and not individual object level).
+ 3. Remove any **AllUsers** or **allAuthenticatedUsers** roles, as these allow
+ public access.
+ 4. Assign only required roles (e.g., `Storage Admin` or
+ `Storage Object Viewer`) to specific users or groups. If you need a bucket
+ to have public access for its purpose (e.g. CDN buckets) :
+ 5. Document why this bucket needs to be public in the evidence section
+ 6. Disable **Uniform Bucket-Level Access** and proceed at the bucket level.
+ For each:
+ 1. Select your bucket
+ 2. Under **Bucket Permissions**, remove any **AllUsers** or
+ **allAuthenticatedUsers** roles
+- Remove the default network The default network in GCP rely on a set of
+ rules/access that can’t be disabled and are “unsafe”. That is why it is better
+ to create your own network.
+
+
+ 1. Once the default network is no longer used, go to [VPC networks](https://console.cloud.google.com/networking/networks/list) on your Google Cloud Console
+ 2. Click the network named `default`.
+ 3. Click DELETE VPC NETWORK at the top of the page.
+- Restrict public SSH access If you need to enable access to your system,
+ leverage **Google Cloud Identity-Aware Proxy (IAP)** as a secure alternative
+ to direct SSH. IAP will let you access your VMs via SSH without exposing them
+ publicly, it eliminates the need for public IPS or open SSH ports.
+ 1. In **GCP Console**, go to **Identity-Aware Proxy** and enable it for the
+ project.
+ 2. Grant the user or group with **IAP-secured Tunnel User** (network access)
+ and **Compute Instance Admin** (SSH permissions) roles.
+ 1. It works even for external users as long as they have a google account.
+ To access the VMs, user need to run a command locally via the **gcloud
+ CLI** to tunnel SSH traffic through IAP:
+ ```bash
+ gcloud compute ssh --tunnel-through-iap
+ ```
+
+## Evidence
+
+- Screenshot showing your storage bucket configuration.
+- Screenshot showing your networks.
diff --git a/controls/core/network/COR.NET.002_penetration_test.md b/controls/core/network/COR.NET.002_penetration_test.md
new file mode 100644
index 000000000..f5ff5b279
--- /dev/null
+++ b/controls/core/network/COR.NET.002_penetration_test.md
@@ -0,0 +1,27 @@
+---
+id: "COR.NET.003"
+category: "core/network"
+revision-version: 1
+revision-date: "2024-01-12"
+estimate-time: "30m"
+necessity: "optional"
+frameworks:
+ - name: "soc2"
+ sections: ["CC3.2", "CC4.1", "CC8.1"]
+---
+
+# Run a penetration test
+
+## Purpose
+
+It is a good way to safeguard your company’s data. It is a real-life simulation
+of attack scenarios on your company: it enables you to identify potential
+vulnerabilities that can be fixed before being exploited.
+
+## Implementation
+
+Schedule a penetration test with a third party.
+
+## Evidence
+
+Your penetration test report.
diff --git a/controls/core/network/COR.NET.002_web_application_firewall.md b/controls/core/network/COR.NET.002_web_application_firewall.md
new file mode 100644
index 000000000..f7c750fc0
--- /dev/null
+++ b/controls/core/network/COR.NET.002_web_application_firewall.md
@@ -0,0 +1,50 @@
+---
+id: "COR.NET.002"
+category: "core/network"
+revision-version: 1
+revision-date: "2024-01-12"
+estimate-time: "30m"
+necessity: "optional"
+frameworks:
+ - name: "soc2"
+ sections: ["CC6.1", "CC6.6"]
+---
+
+# Set-up a WAF
+
+## Purpose
+
+A web application protection service acts as a security shield that:
+
+Filters malicious traffic (SQL injections, XSS attacks) Masks your server's real
+IP address Blocks DDoS attacks and malicious bots Controls request rates to
+prevent abuse
+
+This ensures your applications stay secure and available while legitimate
+traffic flows normally.
+
+## Implementation
+
+### Cloudflare
+
+1. **Sign up for Cloudflare**: Go to [Cloudflare](https://www.cloudflare.com/)
+ and create an account.
+2. **Add your domain**: Enter your website’s domain and let Cloudflare scan
+ existing DNS records.
+3. **Update your DNS**: Change your domain's nameservers to Cloudflare’s
+ nameservers as provided in your Cloudflare dashboard.
+4. **Configure your security settings**:
+ - **Enable the Web Application Firewall (WAF)**: Set up rules to block
+ threats like SQL injections and XSS attacks.
+ - **Enable DDoS Protection**: Configure DDoS settings to prevent service
+ interruptions.
+5. **Optional - Set up Access controls**:
+ - Use **IP Access Rules** to allow or block specific IPs.
+ - Configure **Rate Limiting** to prevent excessive requests that could signal
+ attacks.
+6. **Review and Test**: Ensure that your website operates smoothly, and verify
+ that rules are correctly blocking or allowing traffic.
+
+## Evidence
+
+- Screenshot of your WAF configuration.