Protecting connectivity.
WHAT TO SEPARATE
Customer networks from each other Management networks from production Facility systems from customer systems
WHY MANAGEMENT SEPARATION MATTERS
Remote management interfaces provide complete control of a server.
WHAT THAT MEANS
They must never be reachable from the internet.
WHAT TO RESTRICT
Access to management, to specific addresses or a private path.
WHAT TO CONFIGURE
Firewalls at the boundary Default deny, allowing only what is needed
WHAT TO NEVER EXPOSE
Management interfaces Databases Administrative services
WHY
Anything reachable is found by scanning within hours.
WHAT TO MONITOR
Traffic patterns Unexpected outbound connections Authentication attempts against management interfaces
WHY OUTBOUND MATTERS
A compromised server communicates outward, and that is frequently the first sign.
WHAT FACILITIES TYPICALLY PROVIDE
Protection at the facility level, and sometimes mitigation services.
WHAT REMAINS YOURS
Your own equipment's configuration and security.
WHAT TO ESTABLISH
Exactly where that boundary lies.