Security policy is critical infrastructure
An essential system is one whose failure would cause intolerable harm to customers, markets, or public safety.
Regulatory bodies consider certain systems as essential, with failure potentially causing significant harm to customers, markets, or public safety. Payment platforms in clearing banks and SCADA networks in power distributors are examples of such systems. The security policy control plane, composed of governance rules, determines which systems can communicate with each other, blocks specific connections, and identifies exceptions.
Misconfigured segmentation rules during cloud migrations or temporary broad access granted to development subnets can disrupt critical services. Despite this, many organizations manage their policy environments as routine tasks, adding rules through change requests and rarely examining them against intended outcomes. Ownership of rules disperses, making it difficult to understand why certain rules were implemented.
The FCA and Ofgem expect regulated firms to demonstrate ongoing compliance with defined security outcomes in their policy environments. New regulations will extend similar expectations to data centers, managed service providers, and critical suppliers. Most policy environments were not intentionally designed to meet these standards; rather, they accumulate over time as a by-product of delivery projects.
Continuous evidence of intentional access is now required, rather than relying on documentation that only captures a single point in time.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.