Tietoliikenneverkon vyöhykkeistäminen ja suodatussäännöstöt on toteutettava vähimpien oikeuksien (least privilege) ja monitasoisen suojaamisen (defence in depth) periaatteiden mukaisesti.
Communication network segmentation and filtering rules shall be implemented in accordance with the principle of minimum access rights in the relevant security class.
In processing environments of security classes IV to II, the requirement may be met by implementing the following measures in addition to those mentioned above:
4) Monitor and restrict data flows between network zones, allowing only pre-approved, operationally essential data exchanges (default-deny)
The zoning and filtering provisions of the communication network shall be implemented in accordance with the principle of multi-level protection.
The division of the communication network within a given security class into separate network areas (zones and segments) may mean, for example, appropriate workstation and server separation from a data protection point of view, also covering possible project-specific separation needs.
The requirement can be met by the following measures:
Digiturvamallissa kaikki vaatimuskehikkojen vaatimukset kohdistetaan universaaleihin tietoturvatehtäviin, jotta voitte muodostaa yksittäisen suunnitelman, joka täyttää ison kasan vaatimuksia.