Segment and Separate
February 1, 2024 · View on GitHub
(Back)
Objective
Segment and separate information based on sensitivity of information.
Applicable Service Models
IaaS, PaaS
Note
The following guardrail is not applicable to SaaS. The cloud service provider is responsible for the management and security of the network and this responsibility is included as part of the SaaS offering. Refer to section 4.3 of Guidance on Defence in Depth for Cloud-Based Services (ITSP.50.104) to understand key considerations for cloud network segmentation.
Mandatory Requirements
| Activity | Validation |
|---|---|
|
|
Additional Considerations
| Activity | Validation |
|---|---|
|
|
References
- Direction on the Secure Use of Commercial Cloud Services: Security Policy Implementation Notice (SPIN) 2017-01, subsection 6.2.4
- Cyber Centre’s top 10 IT security actions, number 5
- network security zoning guidance in Baseline Security Requirements for Network Security Zones (ITSP.80.022) and Network Security Zoning (ITSG-38)
- Guidance on Defence in Depth for Cloud-Based Services (ITSP.50.104), subsections 4.3 and 4.5
Related security controls from ITSG-33
AC‑4, SC‑7