4.1 Secure Network Architecture
4.1 Secure Network Architecture
Secure network architecture determines how systems communicate, where trust boundaries exist and how traffic is separated, protected, routed and monitored.
For CISSP, the goal is not simply to memorise network technologies. You need to understand how architecture decisions affect confidentiality, integrity, availability and the ability of an attacker to move through an environment.
Connect
Understand how systems communicate through layered network architectures.
PROTOCOLS & FLOWSSeparate
Divide networks and workloads according to trust and business need.
SEGMENTATIONObserve
Understand network behaviour and identify abnormal or dangerous activity.
VISIBILITYThe Big Idea
A secure network should not allow every connected system to communicate freely with every other system.
Architecture should determine:
Secure Network Architecture
Connect ยท Segment ยท Protect ยท Control ยท Observe
What You Need to Understand
How network communication is divided into layers.
Addressing and delivery models.
IPsec, SSH and TLS.
Encapsulation and security across protocol layers.
Different types of traffic sharing infrastructure.
Topology, network planes and forwarding behaviour.
Bandwidth, throughput, latency, jitter and signal quality.
North-south and east-west communication.
Separate infrastructure, out-of-band and air gaps.
VLANs, VPNs, VRFs and virtual domains.
Fine-grained workload and service isolation.
Ingress, egress and peering.
Wi-Fi, Bluetooth, Zigbee and satellite.
4G and 5G architectures.
Distributed delivery of content closer to users.
Software-controlled and virtualised networking.
Logically isolated cloud networking.
Observability, traffic management, capacity and fault handling.
๐งฑ The OSI Model Seven layers for understanding network communication
The Open Systems Interconnection model divides network communication into seven conceptual layers.
For CISSP, it is useful because security controls and attacks often operate at different layers.
| Layer | Name | Main Role | Examples / Concepts |
|---|---|---|---|
| 7 | Application | Services used by applications | HTTP, DNS, SMTP |
| 6 | Presentation | Data representation, encoding, encryption concepts | Formatting, compression, encoding |
| 5 | Session | Establish and manage communication sessions | Session establishment and coordination |
| 4 | Transport | End-to-end transport | TCP, UDP, ports |
| 3 | Network | Logical addressing and routing | IPv4, IPv6, routers |
| 2 | Data Link | Local network delivery | Ethernet, MAC addresses, switches, VLANs |
| 1 | Physical | Transmission of signals | Copper, fibre, radio |
OSI Layers - Top to Bottom
The OSI model is primarily a conceptual troubleshooting and architecture tool.
Real-world protocols do not always fit perfectly into one isolated OSI layer.
OSI Memory Aids
All People Seem To Need Data Processing
Application
Presentation
Session
Transport
Network
Data Link
Physical
Please Do Not Throw Sausage Pizza Away
Physical
Data Link
Network
Transport
Session
Presentation
Application
๐ฆ Encapsulation & Protocol Data Units Data gains additional information as it moves down the stack
PDU Memory Aid
Data โ Segment โ Packet โ Frame โ Bits
Each relevant layer adds information needed to perform its function, such as transport ports, network addresses or local-link addressing.
๐ TCP/IP Model The practical model underlying modern IP networking
| TCP/IP Layer | Approximate OSI Mapping | Examples |
|---|---|---|
| Application | OSI 5 - 7 | HTTP, DNS, SMTP, SSH |
| Transport | OSI 4 | TCP, UDP |
| Internet | OSI 3 | IPv4, IPv6 |
| Network Access | OSI 1 - 2 | Ethernet, Wi-Fi, physical media |
OSI vs TCP/IP
๐ TCP vs UDP Two important transport approaches
Connection-oriented transport that provides mechanisms for reliable, ordered delivery.
Connectionless datagram transport with less transport-layer overhead and no built-in guarantee that data arrives.
An application can implement reliability or recovery itself when its architecture requires it.
๐ฎ IPv4 & IPv6 Logical addressing and packet delivery
| IPv4 | IPv6 | |
|---|---|---|
| Address Size | 32 bits | 128 bits |
| Typical Representation | 192.0.2.10 | 2001:db8::10 |
| Broadcast | Supported | No traditional broadcast |
| Multicast | Supported | Supported and heavily used |
| Anycast | Can be used | Supported |
IPv6 introduces different addressing, discovery and operational behaviours that must be included in security architecture, filtering and monitoring.
Unicast ยท Broadcast ยท Multicast ยท Anycast
One sender communicates with one destination.
ONE โ ONE
One sender targets all hosts in an applicable broadcast domain.
ONE โ ALL
One sender targets members of a particular group.
ONE โ GROUP
Multiple systems advertise or represent the same service address and routing delivers traffic to an appropriate instance, commonly the topologically closest.
ONE โ ONE OF MANY
Delivery Memory Aid
๐ Secure Protocols Protect communication at different parts of the network stack
Provides security services for IP communications at the network layer.
Commonly associated with site-to-site and network-layer VPN architectures.
Provides secure remote shell and related secure communication capabilities.
Frequently used for administrative access.
Protects communication used by many application protocols.
HTTPS is a common example of HTTP protected using TLS.
Different technologies protect traffic at different architectural layers and therefore solve different problems.
๐ก๏ธ IPsec Protect IP packets at the network layer
Encapsulating Security Payload can provide confidentiality and additional security services depending on configuration.
Authentication Header provides integrity and authentication-related protection but does not provide confidentiality.
Transport vs Tunnel Mode
Protects the payload of the original IP packet while retaining the original outer IP header.
Encapsulates the original IP packet inside a new protected packet.
Common in gateway-to-gateway VPN architecture.
IPsec
๐ช Implications of Multilayer Protocols Protocols can be nested inside other protocols
Network traffic frequently contains one protocol encapsulated inside another.
Security Implications
Encryption may prevent intermediate devices from inspecting the protected content.
One protocol can carry another through parts of the network.
Controls that understand only the outer protocol may not understand what is carried inside it.
Additional headers increase packet size and can affect effective transmission capacity.
Additional encapsulation must be considered when managing maximum packet sizes.
Multiple protocol layers make communication paths more complex to analyse.
Multilayer Protocol Risk
๐ Converged Protocols & Networks Different workloads sharing common infrastructure
Convergence allows different types of traffic and services to use shared network infrastructure.
Voice, storage and application traffic may historically have used separate infrastructure.
Multiple traffic types share common switching and transport infrastructure.
Security Considerations
Different workloads may still require logical separation.
A shared infrastructure failure can affect multiple services.
Time-sensitive traffic may require prioritisation.
Different traffic types may require different security visibility.
Multiple services may fail together if they depend on the same underlying network infrastructure.
๐ธ๏ธ Network Topology How network nodes and paths are arranged
Endpoints connect through a central network device.
Multiple paths exist between network nodes.
Direct communication path between two locations or devices.
Spoke networks communicate through a central hub.
Data-centre topology designed to provide predictable paths between large numbers of connected workloads.
Older topology concepts that remain useful when recognising network architecture.
Centralisation can simplify control but may create concentration or availability dependencies.
Multiple paths can improve resilience but increase architecture and monitoring complexity.
โ๏ธ Data, Control & Management Planes One of the most useful network-architecture distinctions
Forwards actual user and application traffic according to existing forwarding decisions.
MOVE THE TRAFFIC
Determines how traffic should be routed or forwarded.
DECIDE THE PATH
Allows administrators and management systems to configure, observe and maintain network infrastructure.
MANAGE THE NETWORK
A routing protocol learns which path should be used.
Control plane.
The router forwards a customer's packet according to that information.
Data plane.
An administrator connects to configure the router.
Management plane.
An attacker with administrative control of network devices may be able to change routing, filtering and monitoring behaviour.
Network Planes
โก๏ธ Cut-Through vs Store-and-Forward How switches handle frames before forwarding
Begins forwarding after enough of the frame has been received to determine where it should go.
Lower delay, less complete validation before forwarding.
Receives the complete frame before forwarding it.
This allows the device to check the completed frame before sending it onward.
More validation, potentially more latency.
Forwarding
Bandwidth ยท Throughput ยท Latency ยท Jitter ยท SNR
The theoretical or configured capacity of a communication path.
HOW MUCH COULD FLOW?
The amount of useful traffic actually being successfully transferred.
HOW MUCH IS FLOWING?
Delay associated with delivering communication.
HOW LONG?
Variation in packet-delivery timing.
HOW CONSISTENT IS THE DELAY?
Relationship between the useful signal and unwanted noise.
HOW CLEAR IS THE SIGNAL?
A connection may have enough bandwidth but still produce poor voice quality because latency or jitter is excessive.
Performance Memory Aid
โ๏ธ North-South vs East-West Traffic Understand where traffic is moving
Traffic moving into or out of an environment or between major architectural tiers.
Examples include internet users communicating with public applications.
Traffic moving laterally between internal systems, workloads, servers or services.
Examples include communication between microservices or internal application and database tiers.
An attacker who compromises one internal workload may attempt to move laterally through east-west traffic paths.
Traffic Flows
Network Segmentation
Segmentation divides a larger environment into smaller security zones.
Communication between those zones can then be controlled according to business and security requirements.
Compromise of one segment should not automatically provide unrestricted access to every other part of the organisation.
๐ Physical Segmentation Separate networks using physical infrastructure or paths
Different networks can use distinct switches, cabling and other hardware.
A system or network is intentionally isolated from direct network connectivity with other environments.
Administrative communication uses a path separate from ordinary production traffic.
Management traffic shares the same general network infrastructure as production communication.
Physical isolation reduces direct network attack paths, but removable media, maintenance devices, personnel and supply-chain paths can still introduce risk.
Management Networks
๐งฉ Logical Segmentation Separate traffic while sharing physical infrastructure
Virtual Local Area Network logically separates Layer 2 network domains.
Virtual Routing and Forwarding allows separate routing instances to exist on shared routing infrastructure.
Creates a logical communication path across another network and commonly uses cryptography to protect the traffic.
Allows infrastructure to support logically separate security or administrative contexts.
A misconfigured routing, firewall or virtualisation policy can undermine logical segmentation even though the architecture appears separated on paper.
Physical vs Logical
๐งฌ Microsegmentation Apply fine-grained controls between individual workloads or services
Traditional segmentation may separate broad groups such as users, applications and databases.
Microsegmentation applies much more granular control.
Possible Technologies
100 application servers exist inside one application VLAN.
They may all be able to communicate with each other unless additional controls exist.
Application Server A is allowed to communicate only with:
Identity Service + Payment API + required database service.
Unnecessary lateral communication is blocked.
Segmentation Scale
๐ก๏ธ Zero Trust Network Architecture Network location alone should not create implicit trust
Traditional network designs often placed significant trust in systems simply because they were located inside the organisational network.
Zero trust changes the emphasis toward protecting individual resources and making access decisions based on stronger contextual information.
A compromised internal system should not automatically receive broad access simply because of its network location.
Access is still granted.
The difference is that access decisions should be explicitly evaluated rather than assumed from location alone.
Zero Trust
๐ Edge Networks Where the organisation connects to other networks
Traffic entering an environment.
IN
Traffic leaving an environment.
OUT
Networks establish connectivity relationships allowing traffic to move between their routing domains.
Edge Security Questions
Network architecture should not focus only on stopping malicious traffic entering.
Controlling outbound communication can help reduce data exfiltration, command-and-control communication and accidental exposure.
๐ถ Wireless Networks Communication can extend beyond the physical walls of the organisation
Wireless technologies transmit through radio or other non-wired media, changing the physical attack surface.
Common local wireless networking technology.
Short-range wireless connectivity between devices.
Low-power wireless technology often associated with IoT and automation environments.
Provides communication across large geographic distances using satellite infrastructure.
Wireless Architecture Risks
A wired network normally requires physical connection to network infrastructure.
A wireless signal may extend into:
Wireless architecture must consider authentication, encryption, segmentation and actual radio coverage.
๐ฑ Cellular & Mobile Networks 4G and 5G extend enterprise communication beyond traditional LANs
Mobile networks provide wide-area connectivity through carrier infrastructure.
Security Considerations
Devices and subscribers require appropriate authentication.
The organisation depends on infrastructure outside its direct control.
Communication may cross additional network and trust boundaries.
Different services and network functions may require separation.
Control and management functions require strong protection.
Coverage, congestion and provider outages affect connectivity.
๐ Content Distribution Networks - CDN Distribute content closer to users
Benefits
Security Considerations
A public application uses a CDN for protection.
However, the origin server remains directly reachable from the internet.
An attacker may bypass the CDN and target the origin directly.
CDN
๐ง Software-Defined Networking - SDN Move more network control into programmable software
Software-defined networking separates network-control logic from the underlying devices that forward traffic.
Advantages
Security Considerations
The controller can become a highly valuable concentration point.
Programmatic management interfaces require strong authentication and authorisation.
Control infrastructure must be resilient.
Automation can deploy both correct and incorrect policy very quickly.
The ability to change the network globally makes the SDN controller especially important to protect.
๐บ๏ธ Software-Defined WAN - SD-WAN Software-driven control of wide-area connectivity
SD-WAN applies software-defined principles to wide-area network connectivity.
Potential Capabilities
Central orchestration and management interfaces require appropriate identity, access, resilience and monitoring controls.
๐ฆ Network Functions Virtualization - NFV Run network functions as software rather than dedicated appliances
Network functions that historically required dedicated hardware may be implemented as virtualised software functions.
The network function now depends on the security of its virtualisation, orchestration, management and underlying compute infrastructure.
SDN vs NFV
โ๏ธ Virtual Private Cloud - VPC Logical network isolation inside cloud infrastructure
A Virtual Private Cloud provides a logically isolated network environment within a cloud platform.
Typical Architecture Concepts
Logical isolation provides architectural capability, but routing, identities, security policies and external connectivity still need secure configuration.
๐๏ธ Network Observability You cannot effectively protect what you cannot understand
Network observability provides information about how infrastructure and traffic are behaving.
Record events from network infrastructure.
Summarises communication relationships and traffic flows.
Detailed packet information may support troubleshooting and investigation where appropriate.
Provides measurements about performance and infrastructure state.
Shows how systems and network paths relate to each other.
Normal behaviour provides context for detecting significant change.
Monitoring only internet-facing boundaries can leave internal lateral communication poorly understood.
๐ฆ Traffic Flow & Shaping Manage how network capacity is consumed
Network architecture may prioritise, limit or shape traffic according to business requirements.
A converged network carries:
Large backup transfers should not necessarily be allowed to consume all available bandwidth and destroy the quality of latency-sensitive voice calls.
Traffic Management Supports
๐ Capacity Management Availability depends on having sufficient resources
Network capacity should support expected normal demand as well as appropriate peaks, growth and resilience requirements.
Exhausted network resources can produce an availability failure even without a traditional security exploit.
๐จ Fault Detection & Handling Secure networks should fail predictably and recoverably
Having a backup path helps only if the architecture can identify the failure and successfully use the alternative path when required.
Designing a Secure Banking Network
Consider a customer-facing banking platform.
Architecture Decisions
Only required public services are reachable.
Cannot freely communicate with every internal resource.
Accepts only required flows from authorised application services.
Management access is separated from ordinary customer traffic.
Internal service-to-service communication is controlled and monitored.
Important traffic and network events are available for monitoring.
The goal is to understand and control every important trust boundary and communication path.
One Server Is Compromised
Assume an attacker compromises one web server.
The web server can communicate freely with:
Large blast radius.
The web server can communicate only with:
Smaller blast radius.
Segmentation
๐ CISSP Scenarios Recognise the network architecture principle
A security engineer is analysing IP routing between networks.
Which OSI layer is most relevant?
Layer 3 - Network.
A switch processes Ethernet frames using MAC addresses.
Which OSI layer?
Layer 2 - Data Link.
An application uses TCP ports for end-to-end communication.
Which OSI layer?
Layer 4 - Transport.
One packet is sent directly to one destination host.
Delivery type?
Unicast.
Traffic is sent to all members of a particular subscribed group.
Delivery type?
Multicast.
Several geographically distributed servers represent the same service address and routing directs users to an appropriate instance.
Delivery concept?
Anycast.
A site-to-site VPN needs to protect IP traffic between two network gateways.
Which protocol family is particularly relevant?
IPsec.
An administrator requires an encrypted command-line session to a network device.
Which protocol?
SSH.
Web application traffic requires cryptographic protection between a browser and server.
Which protocol is most relevant?
TLS.
An organisation places users and critical database servers on different VLANs.
Which concept?
Logical segmentation.
Two networks use entirely separate switches and cabling.
Which concept?
Physical segmentation.
Security policy restricts communication between individual application workloads even though they exist in the same broad cloud environment.
Which architecture?
Microsegmentation.
A user is located on the internal corporate LAN but must still authenticate and satisfy access policy before reaching a protected resource.
Which principle?
Zero trust.
Traffic travels between two internal microservices.
Which traffic-flow term?
East-west.
Customer traffic enters the organisation from the internet.
Which traffic-flow term?
North-south.
A routing protocol determines the best network path.
Which network plane?
Control plane.
A router sends a normal application packet according to its forwarding table.
Which plane?
Data plane.
An engineer changes the configuration of a network switch.
Which plane?
Management plane.
Network administration uses infrastructure that is physically or logically separated from production traffic.
Which concept?
Out-of-band management.
Two servers are placed on an air-gapped network.
Management claims this makes compromise impossible.
What is wrong with the statement?
Air gaps remove direct network connectivity but other attack paths, such as removable media and human interaction, can still exist.
Voice traffic becomes unusable because packets arrive with highly inconsistent delays.
Which metric?
Jitter.
A 10 Gbps network connection delivers only 6 Gbps of actual useful traffic.
10 Gbps represents what?
Bandwidth / capacity.
6 Gbps represents what?
Throughput.
The organisation virtualises firewalls and routers instead of using a separate physical appliance for every function.
Which concept?
Network Functions Virtualization - NFV.
Network behaviour is centrally programmed through a controller and APIs.
Which architecture?
Software-Defined Networking - SDN.
A public web service uses a CDN but the origin server remains directly reachable from anywhere on the internet.
Primary architectural concern?
Attackers may bypass the CDN and directly target the origin.
A cloud environment separates internet-facing applications, application services and databases into different logical network areas.
Which concept?
VPC segmentation.
A company monitors traffic entering from the internet but has almost no visibility into internal server-to-server communication.
Which visibility gap?
East-west traffic visibility.
A switch begins transmitting a frame before receiving the complete frame.
Which forwarding approach?
Cut-through.
A switch receives the entire frame and validates it before forwarding.
Which approach?
Store-and-forward.
Several network security controls are configured correctly, but demand grows until all available network capacity is consumed.
Which management activity was insufficient?
Capacity management.
Recognise the Clue Words
MAC / Ethernet
Local frames.
Layer 2IP / Router
Logical addressing and routing.
Layer 3TCP / UDP / Ports
End-to-end transport.
Layer 4Data โ Segment โ Packet โ Frame
Move down the stack.
EncapsulationOne โ One
Individual destination.
UnicastOne โ Group
Group communication.
MulticastOne of Many
Same service in multiple places.
AnycastNetwork-Layer VPN
Protect IP traffic.
IPsecSecure Command Line
Administrative communication.
SSHSecure Web Traffic
Application communication protection.
TLSTraffic Inside Traffic
Nested protocols.
Encapsulation / Multilayer ProtocolVoice + Storage + Data
Shared infrastructure.
ConvergenceMove Traffic
Packet forwarding.
Data PlaneChoose Route
Network decisions.
Control PlaneConfigure Network
Administration.
Management PlaneCapacity
Potential amount.
BandwidthActual Transfer
Real achieved rate.
ThroughputDelay
Time taken.
LatencyVariable Delay
Especially important for voice/video.
JitterInto / Out of Environment
Perimeter-style flow.
North-SouthServer-to-Server
Lateral traffic.
East-WestSeparate Hardware
Distinct infrastructure.
Physical SegmentationVLAN / VRF
Shared hardware, logical separation.
Logical SegmentationWorkload-Level Controls
Very granular isolation.
MicrosegmentationNo Trust Based on Location
Explicit policy decisions.
Zero TrustTraffic Entering
Network edge.
IngressTraffic Leaving
Network edge.
EgressDistributed Content
Closer to users.
CDNCentral Network Controller
Programmable networking.
SDNVirtual Firewall / Router
Software network functions.
NFVIsolated Cloud Network
Subnets and cloud routing.
VPCLogs / Flows / Telemetry
Understand network behaviour.
Observabilityโ ๏ธ Common CISSP Mistakes Network questions frequently test architecture rather than commands
OSI uses seven conceptual layers while the commonly used TCP/IP model groups functionality into fewer layers.
Traditional switching is primarily associated with Layer 2.
Routing is primarily associated with Layer 3.
Bandwidth represents capacity.
Throughput represents what is actually being transferred.
Latency is delay.
Jitter is variation in delay.
IPv6 changes several aspects of addressing and network operation and should receive its own security consideration.
Encryption may protect data while segmentation, authentication, routing and monitoring remain weak.
Network location alone should not justify unrestricted access.
A VLAN may contain many workloads that can communicate freely unless additional controls restrict them.
Other physical, removable-media and human paths may remain.
They may share the same physical path, provider, device or management infrastructure.
Attackers can move laterally using east-west communication.
SDN focuses on programmable network control.
NFV virtualises network functions.
Cloud network security still depends on routing, policy, identity and configuration.
The origin must also be architected so attackers cannot simply bypass the CDN.
Visibility is useful only when abnormal behaviour can be analysed and acted upon.
Quick Reference
| If you see... | Think... |
|---|---|
| MAC address / Ethernet frame | OSI Layer 2 |
| IP address / routing | OSI Layer 3 |
| TCP / UDP / port | OSI Layer 4 |
| Data โ Segment โ Packet โ Frame โ Bits | Encapsulation |
| One destination | Unicast |
| Everyone in broadcast domain | Broadcast |
| Defined group | Multicast |
| One instance from several | Anycast |
| Protect IP packets | IPsec |
| Secure administrative shell | SSH |
| Secure application transport | TLS |
| Forward normal traffic | Data Plane |
| Determine routes | Control Plane |
| Configure devices | Management Plane |
| Potential network capacity | Bandwidth |
| Actual transfer rate | Throughput |
| Delay | Latency |
| Variable delay | Jitter |
| Traffic entering or leaving environment | North-South |
| Internal lateral traffic | East-West |
| Separate switches / cabling | Physical Segmentation |
| VLAN / VRF | Logical Segmentation |
| Fine-grained workload isolation | Microsegmentation |
| No implicit trust from network location | Zero Trust |
| Traffic entering | Ingress |
| Traffic leaving | Egress |
| Content cached near users | CDN |
| Programmable controller | SDN |
| Virtual firewall / router | NFV |
| Software-managed WAN | SD-WAN |
| Logically isolated cloud network | VPC |
| Flows, logs and telemetry | Network Observability |
Domain 4.1 Master Memory Aid
Layers ยท Address ยท Protocol ยท Flow ยท Segment ยท Control ยท Observe ยท Resilient
The Network Architect's Questions
Key Takeaways
Secure network architecture controls how systems communicate and where network trust boundaries exist.
The OSI model provides seven conceptual layers, while the TCP/IP model combines network communication into fewer practical layers.
A useful encapsulation memory aid is: Data โ Segment โ Packet โ Frame โ Bits.
Layer 2 is strongly associated with Ethernet frames, MAC addresses and switching, while Layer 3 is associated with IP addressing and routing.
Layer 4 provides transport capabilities through protocols such as TCP and UDP.
IPv4 uses 32-bit addresses while IPv6 uses 128-bit addresses.
Unicast means one-to-one, multicast means one-to-group, broadcast means one-to-all within the applicable broadcast domain, and anycast directs traffic to one suitable instance among multiple instances.
Secure protocols operate at different architectural layers. IPsec protects IP communication, SSH provides secure remote communication and TLS protects many application communication protocols.
Multilayer protocols create security considerations because traffic can be encapsulated and controls may see only part of the complete protocol stack.
Converged networks improve infrastructure efficiency but may concentrate risk when voice, storage and application traffic depend on the same underlying network.
The data plane forwards traffic, the control plane determines paths and the management plane administers the network.
Bandwidth represents capacity, while throughput represents actual successful data transfer.
Latency is communication delay, while jitter is variation in delay.
North-south traffic generally enters or leaves an environment, while east-west traffic moves laterally between internal workloads and systems.
Monitoring only north-south traffic can leave attacker lateral movement through east-west paths poorly visible.
Physical segmentation uses separate infrastructure or communication paths.
Logical segmentation uses technologies such as VLANs, VRFs, VPNs and virtual security domains while sharing underlying infrastructure.
Microsegmentation provides much more granular control between individual workloads and services.
Segmentation reduces unnecessary connectivity, limits lateral movement and reduces the potential blast radius of compromise.
Zero trust removes the assumption that network location alone should create implicit trust.
Edge architecture should consider both ingress and egress communication, including external routing and peering relationships.
Wireless communication changes the physical security boundary because radio signals can extend beyond organisational walls.
CDNs distribute content closer to users but the underlying origin should also be protected against direct bypass.
SDN provides programmable network control, while NFV implements network functions as virtualised software.
SD-WAN applies software-defined control concepts to wide-area network connectivity.
A VPC provides logical cloud network isolation but still requires secure routing, access policies and configuration.
Network observability uses information such as logs, flows, packets, topology and telemetry to understand behaviour.
Capacity and fault management are security considerations because resource exhaustion or infrastructure failure can directly affect availability.
The key CISSP principle is not simply to connect systems securely. It is to permit only necessary communication, protect important flows, minimise implicit trust, reduce blast radius and maintain visibility across the architecture.
๐ Sources & Further Reading Network architecture and protocol references
- ISC2 - CISSP Certification Exam Outline
View the current CISSP Exam Outline - NIST SP 800-207 - Zero Trust Architecture
View NIST Zero Trust Architecture - NIST SP 800-207A - Zero Trust Architecture for Cloud-Native Applications
View NIST cloud-native zero trust guidance - NIST SP 800-215 - Guide to a Secure Enterprise Network Landscape
View NIST secure enterprise network guidance - RFC 8200 - Internet Protocol, Version 6
View the IPv6 specification - RFC 4301 - Security Architecture for the Internet Protocol
View the IPsec security architecture - RFC 8446 - The Transport Layer Security Protocol Version 1.3
View the TLS 1.3 specification - RFC 4251 - The Secure Shell Protocol Architecture
View the SSH protocol architecture
