IT‑IS Networking
Technology › Security Architecture

Security Architecture

Security-by-design across estates with conflicting statutory obligations — where the classification scheme has to survive a court rather than an audit.

Enterprise security policy and standards, identity and privilege architecture, and compliance-driven design across CJIS, HIPAA, NIST 800-53, PCI and Florida public records law simultaneously on shared infrastructure.

The firewall estate was run directly, not only designed, across two platform generations: the enterprise Juniper security platform — every rule, every change, every upgrade — and the Cisco ASA platforms serving the library system and the Clerk of Courts data centre, before architecting the Palo Alto Networks multi-tenant platform that succeeded them.

Being the person who lives with the rule base is what makes the next architecture better than the last one.

A recurring design principle, learned the hard way: security controls that take the network with them when they fail do not survive contact with an operations team. The disaster recovery path was built with diverse carrier circuits and aggregated links into redundant next-generation firewall pairs in high availability with hardware bypass, so a failure of the inspection layer degraded to open rather than to down.