workflow
Network Segmentation & Boundary Rule Management
Network Segmentation & Boundary Rule Management as a decision-aware operator workflow covering trust-zone maintenance, gated rule-change implementation, boundary threat monitoring, the quarterly segmentation and rule-set review, and cross-domain exchange-policy enforcement. This cycle runs on the EXISTING boundary-protection Control item (domains network_communications_security; framework NIST 800-53, NIST CSF 2.0, ISO 27001, SOC 2; frequency quarterly; the boundary control owner as control_owner) — each quarterly run is one workflow instance attached to and enriching that Control, never a new control record. In scope: the trust-zone model, the managed interfaces (firewalls, gateways, proxies) mediating traffic between zones, the external boundary and key internal boundaries, and the cross-domain interconnection points, all under a deny-by-default baseline (NIST 800-53 SC-7, SC-16, SC-46; NIST CSF 2.0 PR.IR-01; ISO 27001 A.8.22; SOC 2 CC6.6). No upstream workflow feeds this cycle; it self-seeds from its own prior-cycle carry-forward — open corrective-action Issue items linked to the Control plus the prior run's closure record and archived rule-change record log. Named deliverables: the reconciled trust-zone model, the verified rule-change record log, the boundary threat-monitoring summary, the cross-domain exchange-policy enforcement report, the quarterly segmentation & rule-set review report, the boundary-posture dashboard, and corrective-action Issues linked to the Control. Downstream, it hands off only to its own next cycle via the carry-forward closure record; a confirmed intrusion is escalated to the incident-response workflow (out of scope), as are host/endpoint controls.
Record JSON · Open in map · Data retrieval guide
Catalog revision: f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e. A connection does not establish full coverage.
Attributes
- domain
- controls
- department
- it
- lineOfDefense
- operate
Details
- teams
- it
- domains
- controls
- standards
- nist-800-53
- nist-csf-2
- iso-27001
- soc2
- sourceTemplateId
- workflow-library:controls-network-segmentation-boundary-rule-management
- releaseId
- sha256:374b2477ca13a885488cdd1e4d64835b2fb29e081f7d63b58029a964c97a36cd
- canonicalUrl
- https://assureswarm.com/workflows/all/?w=controls-network-segmentation-boundary-rule-management
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- operate
- controls
- UC-NET-01
- UC-NET-14
- UC-DATA-11
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:374b2477ca13a885488cdd1e4d64835b2fb29e081f7d63b58029a964c97a36cd
Connections
- Network Segmentation & Boundary Rule Management operates UC-NET-01 — Segment networks and defend the external boundary
- Network Segmentation & Boundary Rule Management operates UC-DATA-11 — Control data flows, leakage, and cross-border transfers
- Network Segmentation & Boundary Rule Management operates UC-NET-14 — Enforce policy on cross-domain information exchange