ASUME

Trust Center

Network Security

Cloud and network controls ASUME documents today. Dedicated WAF, IDS/IPS, and SIEM artefacts are not independently verified.

Environment separation

ASUME separates customer-facing environments from administrative ones and configures cloud-provider controls to limit who can reach production. Current infrastructure and network practices are described in Security Measures.

A published network-segmentation standard covering every internal segment is still being formalized and is not independently verified.

Restricted administrative interfaces

Administrative interfaces are restricted and separated from customer-facing environments where technically applicable, as described in Security Measures.

Extending these restrictions uniformly across every internal tool remains in progress.

Security information and event management

ASUME is building a security information and event management (SIEM) capability so that logs and events from infrastructure and applications can be reviewed in one place. Current production logging is described in Security Measures.

A dedicated SIEM platform, 24/7 analyst coverage, and threat-intelligence enrichment are not yet in place and are not independently verified.

Intrusion detection and prevention

Dedicated intrusion detection (IDS) and intrusion prevention (IPS) systems that continuously monitor and block malicious traffic are a roadmap item.

Until they are in place, network and infrastructure controls follow Security Measures. Listing IDS/IPS here is not a representation that those products are deployed today.

Web application firewall

A dedicated web application firewall (WAF) in front of public-facing applications is a roadmap item.

Until it is published, public-facing access is protected by the infrastructure and network controls in Security Measures. Listing a WAF here is not a representation that one is deployed today.