Protecting the surrounding environment.
WHAT TO SEPARATE
Device networks from other networks.
WHY
Compromised devices must not reach business systems.
WHAT SEGMENTATION SHOULD ENFORCE
Devices reaching only what they need No device-to-device communication, unless required No inbound connections from outside
WHY NO INBOUND
Devices should initiate outward, never accept connections.
WHAT THAT AVOIDS
Exposure to scanning and direct attack.
WHAT GATEWAYS SHOULD DO
Terminate device protocols Enforce policy Forward only what is permitted
WHAT TO MONITOR
Unexpected destinations Unexpected volumes Devices attempting connections they should not
WHY DESTINATIONS SPECIFICALLY
A compromised device contacting an unknown address is a clear signal.
WHAT TO BASELINE
Normal traffic per device type.
WHAT TO DO ON DEVIATION
Isolate, and investigate.
WHAT TO PROVIDE
The ability to isolate a device or a group, immediately.
WHAT TO NEVER PLACE ON A GENERAL NETWORK
Devices with no update path.
WHAT TO ADVISE CUSTOMERS
To place devices on a separate network where possible.
WHAT TO DOCUMENT
What network access your devices require.