Security policy is critical infrastructure
In banking and utilities, regulators define certain systems as essential. An essential system is one whose failure would cause intolerable harm to customers, markets, or public safety. A payment platform in a clearing bank or a SCADA network in a power distributor, for example, carries the highest governance obligations: continuous monitoring, validated change control, and demonstrable resilience.
SVP for International Business at FireMon.
The policy environment – the accumulated rules across firewalls, cloud controls, and microsegmentation – determines which of those systems can reach each other, which connections are blocked, and which exceptions still apply. Collectively, these rules form the security policy control plane: the governance layer that translates business intent into access decisions across distributed enforcement points.
A misconfigured segmentation rule during a cloudmigration can sever a payment service from its settlement platform; a temporary rule granting broad access from a development subnet into production can...
Copyright of this story solely belongs to techradar.com. To see the full text click HERE