[Agenda]
[Examples]
[Network Partitioning]
[Concepts]
[Policy]
[Process]
[Organization]
[HW-SW]
[Cases studies]
[Conclusion]
[Resources]
Case with network service provider
Customer responsibility
Service Provider responsibility
Yes
Define domains to partition
Yes
Determine service flows between domains and draw them
Yes
Approve and apply the security policy to the service flows
Yes
Apply the service flows to filtering devices
Yes
Audit & validate the filtering devices policies
Yes
Update the service flows drawings
â
The exchange of the security policy between Customer & Service Provider must be formalized
Repudiation must not be possible from both parties
® ©
Hervé Schauer Consultants
December 1999 - 142, rue de Rivoli - F-75001 Paris - France
Phone: +33 141 409 700 - Fax: +33 141 409 709 - Email: <secretariat@hsc.fr>
- Page 63 -