Maintain control of data flow between the organisation and its partners / service providers. An attack can hit the organisation via the systems of a partner or service provider. Traffic to and from these systems should be directed only to the relevant parts of the organisation’s system.
Organisaatiolla on oltava seuraavat palomuurisäännöt asetettuna ja dokumentoituna:
The zoning and filtering provisions of the communication network shall be implemented in accordance with the principle of multi-level protection.
The division of the communication network within a given security class into separate network areas (zones and segments) may mean, for example, appropriate workstation and server separation from a data protection point of view, also covering possible project-specific separation needs.
The requirement can be met by the following measures:
Digiturvamallissa kaikki vaatimuskehikkojen vaatimukset kohdistetaan universaaleihin tietoturvatehtäviin, jotta voitte muodostaa yksittäisen suunnitelman, joka täyttää ison kasan vaatimuksia.