Network Segmentation & Public-System Isolation
• Publicly accessible components are separated from internal systems; public-facing applications are hosted in isolated environments connected only through secure, certificate-based tunnels.
• IoT and operational-technology devices are isolated into restricted, non-routable network zones.
• A web application firewall and DDoS mitigation service protect public-facing applications; this coverage is standard for new builds and is being extended to remaining legacy applications.
Framework Alignment: NIST CSF PR.IR; CIS Control 12, 13; CMMC Level 1 (SC); GDPR Art. 32(1)(b); ISO 27001:2022 A.8.22, A.8.20