Purpose
This standard establishes the requirements for network security, connectivity, segmentation, traffic management, and boundary protection for University-managed technology environments.
The standard defines the controls necessary to protect the confidentiality, integrity, availability, and accountability of network communications while supporting approved academic, research, operational, and regulatory requirements.
Scope
This standard applies to:
- Applications
- Databases
- Data platforms
- Cloud services
- Infrastructure services
- Platform services
- Software-as-a-Service solutions
- Integration services
- Shared services
- Network services
- University-managed technology environments
Network Security Principles
Boundary Protection
Network architectures shall implement appropriate security boundaries that support governance, operational management, workload protection, and institutional requirements.
Least Connectivity
Network connectivity shall be limited to approved and necessary communication paths.
Approved Communications
Network communications shall follow approved connectivity paths and approved architecture requirements.
Defense in Depth
Network security controls shall support layered protection rather than relying upon a single security control or boundary.
Network Isolation and Segmentation
Network architectures shall implement logical or physical segmentation appropriate to:
- Workload classification
- Data classification
- Operational requirements
- Security requirements
- Regulatory requirements
Segmentation should support:
- Workload separation
- Administrative separation
- Operational management
- Security controls
- Risk reduction
Connectivity Requirements
Network communications shall be restricted to approved communication paths.
Connectivity decisions shall consider:
- Business requirements
- Security requirements
- Operational requirements
- Data protection requirements
- Regulatory requirements
Ingress Controls
Inbound connectivity shall be explicitly governed, managed, and monitored.
Unauthorized inbound access paths shall not be permitted.
Inbound connectivity should:
- Support approved business functions
- Follow approved architecture patterns
- Support monitoring and auditability
- Minimize unnecessary exposure
Egress Controls
Outbound communications shall follow approved connectivity requirements and approved security controls.
Outbound connectivity should:
- Support approved business requirements
- Follow approved communication paths
- Support monitoring requirements
- Support investigation requirements
Private Connectivity
Private connectivity mechanisms should be used whenever supported by the platform, service, application, or workload architecture.
Private connectivity supports:
- Reduced exposure
- Improved security posture
- Service isolation
- Controlled access paths
Identity Integration
Network architectures shall support approved enterprise identity services required for authentication, identity governance, authorization, and access management.
Identity-related communications shall follow approved connectivity and security requirements.
Monitoring Integration
Network architectures shall integrate with approved monitoring and logging capabilities.
Network monitoring shall support:
- Traffic visibility
- Operational troubleshooting
- Security investigations
- Audit activities
- Incident response activities
Operational Visibility
Network services shall generate monitoring and audit information sufficient to support:
- Operational support
- Security investigations
- Compliance activities
- Audit reviews
- Architecture governance
Data Protection Alignment
Network architectures shall support applicable data protection requirements including:
- Encryption requirements
- Data protection controls
- Auditability requirements
- Monitoring requirements
Network implementations shall not circumvent approved protection controls.
Shared Services Connectivity
Workloads may communicate with approved enterprise shared services when authorized through applicable standards, governance requirements, and architecture patterns.
Shared service communications shall:
- Follow approved connectivity paths
- Support monitoring requirements
- Support operational management
- Support auditability requirements
Workload Classification Alignment
Innovation Workloads
Innovation workloads shall implement network protections appropriate to the Innovation workload control baseline.
Enterprise Workloads
Enterprise workloads shall implement network security controls, segmentation, monitoring, and approved connectivity appropriate to the enterprise workload control baseline.
Regulated Workloads
Regulated workloads shall implement enhanced network controls, segmentation, visibility, connectivity governance, boundary protection, and monitoring requirements.
Governance Alignment
Network architectures shall align with applicable governance requirements, standards, architecture decisions, and approved patterns.
Network implementations shall support governance visibility, compliance activities, and operational accountability.
Architecture Review
Network implementations that materially deviate from approved standards, architecture decisions, or approved patterns require architecture review before implementation.
Exceptions
Exceptions to this standard require documented approval through the approved architecture exception process.