Environment separation
ASUME separates customer-facing environments from administrative ones and configures cloud-provider controls to limit who can reach production. Current infrastructure and network practices are described in Security Measures.
A published network-segmentation standard covering every internal segment is still being formalized and is not independently verified.