IVS-06 Segmentation and Segregation
Segment and segregate provider and tenant access, and access between tenants, so one tenant cannot reach another, and monitor those boundaries.
4
artefacts
1
held by a system
2
at each review
moderate
to go live
SIEM / log platform
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Monitoring of cross-tenant access attempts · SIEM / log platform
periodic reviewEvidence produced at each review
- Technical evidence of enforcement at compute, network and data layers · Cloud console / configuration management
- Testing evidence such as a tenant isolation test · Document repository
governing documentDocuments that govern the control
- Design documentation of the tenant isolation model · Document repository
First move
Start with the 1 of 4 artefacts that already live in a system (SIEM / log platform); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Isolation enforced in the application layer only, with shared data stores underneath
- Provider administrative access crossing tenant boundaries unmonitored
- Isolation never tested adversarially
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetIVS-05 Production and Non-Production Environments · IVS-07 Migration to Cloud Environments