It's
a new world, one in which physical security is less certain,
and in which more and more of a company's lifeblood is held
digitally rather than physically. Companies need to maintain
their ability to withstand any sort of interruption, whether
it is internal, external, or network-related. Companies should
think about more than just data: Think about what you need
to keep your business going, maintain customer satisfaction,
and retain market share, even in the face of a spectacular
interruption. Think about the ways in which you're interconnected
with partners, suppliers, and customers, and work with those
entities to ensure that their lapses don't become yours. More
and more companies are creating highly available and fully
redundant network systems, making preparation for any eventuality
an everyday occurrence, not a reaction to unusual events.
To provide Best-of-Class security solutions,
Cierra Business Solutions uses the same
methodologies of Global corporations such as GM, Wal-Mart,
Citibank, Department of Defense, and NASA among others.
The master blueprint that Cierra Business Solutions builds
upon is the Cisco’s SAFE Blueprint for Security.
Cierra Business Solutions
uses the SAFE Blueprint as a flexible, dynamic blueprint
for security and VPN networks, based on the Cisco’s Architecture
for Voice, Video and Integrated Data (AVVID), that enables
businesses to securely and successfully take advantage of
e-business economies and compete in the Internet economy.
Cisco has significantly enhanced the SAFE Blueprint, and
extended network security and VPN options to small branch
offices, teleworkers, and small-to-medium networks.
Cierra Business Solutions
uses SAFE to emulate as closely as possible the functional
requirements of today's enterprise networks. Implementation
decisions varied depending on the network functionality
required. However, the following design objectives, listed
in order of priority, guided the decision-making process.
Security
and attack mitigation based on policy
Security
implementation throughout the infrastructure (not just on
specialized security devices)
Secure
management and reporting
Authentication
and authorization of users and administrators to critical
network resources
Intrusion
detection for critical resources and subnets
Support
for emerging networked applications
First and foremost, Cierra
Business Solutions uses SAFE as a security
architecture. We at Cierra
Business Solutions feel that a sound architecture
must prevent most attacks from successfully affecting valuable
network resources. The attacks that succeed in penetrating
the first line of defense, or originate from inside the
network, must be accurately detected and quickly contained
to minimize their effect on the rest of the network. However,
in being secure, the network must continue to provide critical
services that users expect. Proper network security and
good network functionality can be provided at the same time.
The SAFE architecture is not a revolutionary way of designing
networks, but merely a blueprint for making networks secure.
SAFE is also resilient and scalable. Resilience in networks
includes physical redundancy to protect against a device
failure whether through misconfiguration, physical failure,
or network attack. Although simpler designs are possible,
particularly if a network's performance needs are not great,
this document uses a complex design as an example because
designing security in a complex environment is more involved
than in simpler environments.