IVS-08: Network Architecture Documentation
Control Family:
Previous Version:
- Cloud Controls Matrix v3.0.1:
- IVS-13: Network Architecture
Control Statement
Identify and document high-risk environments.
Implementation Guidance
The documents or diagrams should include, but are not limited to, the details below:
- Architecture diagrams, security zone descriptions, and related policies
- All components (physical, logical)
- Hypervisors, workloads, hosts, and networks (physical, virtual), etc.
- Physical site details for each workload
- Traffic flow between various components
- All communication channels, including out-of-band communication channels
- Defined roles and responsibilities
- Security zones, workloads on each host, security levels for the workloads, etc.,
- Identify and document dependencies between the different environments and how they impact the risk assessment.
Auditing Guidance
- Examine the criteria for identifying high-risk environments.
- Examine the inventory of high-risk environments, and periodicity of review.
[csf.tools Note: For more information on the Cloud Controls Matrix, visit the CSA Cloud Controls Matrix Homepage.]
Cloud Control Matrix is Copyright 2023 Cloud Security Alliance.