DRAFT: Network Security Standard

Tags Standard

Purpose

This standard establishes the requirements for network security, connectivity, segmentation, traffic management, and boundary protection for University-managed technology environments.

The standard defines the controls necessary to protect the confidentiality, integrity, availability, and accountability of network communications while supporting approved academic, research, operational, and regulatory requirements.

Scope

This standard applies to:

  • Applications
  • Databases
  • Data platforms
  • Cloud services
  • Infrastructure services
  • Platform services
  • Software-as-a-Service solutions
  • Integration services
  • Shared services
  • Network services
  • University-managed technology environments

Network Security Principles

Boundary Protection

Network architectures shall implement appropriate security boundaries that support governance, operational management, workload protection, and institutional requirements.

Least Connectivity

Network connectivity shall be limited to approved and necessary communication paths.

Approved Communications

Network communications shall follow approved connectivity paths and approved architecture requirements.

Defense in Depth

Network security controls shall support layered protection rather than relying upon a single security control or boundary.

Network Isolation and Segmentation

Network architectures shall implement logical or physical segmentation appropriate to:

  • Workload classification
  • Data classification
  • Operational requirements
  • Security requirements
  • Regulatory requirements

Segmentation should support:

  • Workload separation
  • Administrative separation
  • Operational management
  • Security controls
  • Risk reduction

Connectivity Requirements

Network communications shall be restricted to approved communication paths.

Connectivity decisions shall consider:

  • Business requirements
  • Security requirements
  • Operational requirements
  • Data protection requirements
  • Regulatory requirements

Ingress Controls

Inbound connectivity shall be explicitly governed, managed, and monitored.

Unauthorized inbound access paths shall not be permitted.

Inbound connectivity should:

  • Support approved business functions
  • Follow approved architecture patterns
  • Support monitoring and auditability
  • Minimize unnecessary exposure

Egress Controls

Outbound communications shall follow approved connectivity requirements and approved security controls.

Outbound connectivity should:

  • Support approved business requirements
  • Follow approved communication paths
  • Support monitoring requirements
  • Support investigation requirements

Private Connectivity

Private connectivity mechanisms should be used whenever supported by the platform, service, application, or workload architecture.

Private connectivity supports:

  • Reduced exposure
  • Improved security posture
  • Service isolation
  • Controlled access paths

Identity Integration

Network architectures shall support approved enterprise identity services required for authentication, identity governance, authorization, and access management.

Identity-related communications shall follow approved connectivity and security requirements.

Monitoring Integration

Network architectures shall integrate with approved monitoring and logging capabilities.

Network monitoring shall support:

  • Traffic visibility
  • Operational troubleshooting
  • Security investigations
  • Audit activities
  • Incident response activities

Operational Visibility

Network services shall generate monitoring and audit information sufficient to support:

  • Operational support
  • Security investigations
  • Compliance activities
  • Audit reviews
  • Architecture governance

Data Protection Alignment

Network architectures shall support applicable data protection requirements including:

  • Encryption requirements
  • Data protection controls
  • Auditability requirements
  • Monitoring requirements

Network implementations shall not circumvent approved protection controls.

Shared Services Connectivity

Workloads may communicate with approved enterprise shared services when authorized through applicable standards, governance requirements, and architecture patterns.

Shared service communications shall:

  • Follow approved connectivity paths
  • Support monitoring requirements
  • Support operational management
  • Support auditability requirements

Workload Classification Alignment

Innovation Workloads

Innovation workloads shall implement network protections appropriate to the Innovation workload control baseline.

Enterprise Workloads

Enterprise workloads shall implement network security controls, segmentation, monitoring, and approved connectivity appropriate to the enterprise workload control baseline.

Regulated Workloads

Regulated workloads shall implement enhanced network controls, segmentation, visibility, connectivity governance, boundary protection, and monitoring requirements.

Governance Alignment

Network architectures shall align with applicable governance requirements, standards, architecture decisions, and approved patterns.

Network implementations shall support governance visibility, compliance activities, and operational accountability.

Architecture Review

Network implementations that materially deviate from approved standards, architecture decisions, or approved patterns require architecture review before implementation.

Exceptions

Exceptions to this standard require documented approval through the approved architecture exception process.