54
Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia
4.1.5 Network Segmentation
The implementation of Network Segmentation as part of security- by-design is closely related to the security of the Providers’ infrastructure. Network Segmentation divides the internal network into several isolated zones (such as the Internet Zone, Intranet Zone, and Extranet Zone), thereby limiting lateral movement by attackers in the event of a security breach.
1
Internet Zone is the zone with the lowest level of trust, consisting of public networks such as the World Wide Web. All traffic originating from or directed to the internet must be treated as untrusted traffic. In this context, the role of firewalls, intrusion prevention systems (IPS), and content filtering becomes critical to secure the border between the internet zone and the internal network. Direct access from the internet zone to internal systems must be restricted and only conducted through intermediary systems such as a Demilitarized Zone (DMZ). 6 Intranet Zone is the most trusted zone and is generally accessible only by internal users of an organization. This zone includes critical systems such as internal business applications, file servers, internal databases, and user devices within a controlled environment. It carries a high level of trust and must be logically separated from other zones using firewalls and strict access controls, including segregating access between development and production environments. The intranet is typically not exposed directly to the public internet to avoid potential external attacks 7 .
2
6 William Stallings, Network Security Essentials 7 National Institute of Standards and Technology, NIST Special Publication 800-41 Rev. 1 - Guidelines on Firewalls and Firewall Policy
Made with FlippingBook Ebook Creator