-
Governance
-
Policy
- prod should be protected from events in non prod
- Non related business applications should be aggregated into isolated areas
-
Standards
-
Physical Segregation
- Firewalls
- Loadbalancers/WAFs
- Out of Band Network
- 3rd Party Networks
-
Logical Segregation
- Area segregation
- VLANs
- QoS
-
Baseline
- OWS in different VLAN to other areas
- Stress test and DDOS can occur without impacting other areas
-
Guidelines
- Separate F5 clusters for Areas
- Separate Internal Firewalls for Areas
-
Procedures
- Creation of new VLANs
- Addition of new network hardware
- Addition of new servers
- Addition of new applications
-
Controls
-
scope
-
Deliverables
- network change
- policy
- vlan migration
- Design
- Analysis
- cost
- time
-
Analysis
-
Review
- Current VLANs
- Areas
- Networks
- Design
-
Implementation
- Network
- Datacentre