Enterprise Network Security Model Evaluation
Which security mode should we choose? Depends on the situation. Because it depends on which method is most suitable for your organization, the following problems are summarized:
· How is your organizational collaboration and independence?
· What are the driving or regulatory requirements of regulatory compliance?
· Who are buying, operating, and ultimately responsible for security?
· What are the company's risk preferences?
Therefore, it is necessary to understand the impact of virtualization on enterprises. We need to further explore this thinking process.
In a virtual green environment, most organizations choose to build a continuous model based on the underlying physical network isolation and partitioning. This design mode usually uses a combination of routers and switches as the most basic network-based isolation structure and firewall.
Depending on the capabilities of the computing virtualization platform deployed on the network, servers or security teams may need to use virtual machine-based device security solutions or additional workload policies implemented by super managers. It really depends on the degree of virtualization of the environment and whether the virtualization platform provides such features. In this case, the security team may not be able to choose a security solution.
If you select the hybrid mode, this is usually because the network security and server team are more collaborative and multi-disciplinary. They are all able to achieve automation, and because of mature processes and clearly defined roles and responsibilities, they are more sure to solve problems and eliminate faults. If the workflow is automated, policy namespaces are prone to conflicts, and policy optimization and correctness cannot be ensured.
Please note that as a multi-disciplinary, cross-functional team, you will be involved in content based on the cloud platform and operating model. This may also involve developers, an interesting functional set. At this time, the automation and development and operation methods provide a completely different security mode. In this mode, we will see a small number of physical or virtual device models, and the security is pushed to the application layer itself.
In a virtual environment, enterprise network security can be designed and operated in multiple ways. Technology is only a small part of the puzzle. Culture, practice, and design types involve many issues. To make security really work, You must select a method suitable for the Organization and its team building.