Reference Architecture Diagram + Narrative (policy-driven perimeter for everything)
┌──────────────────────────────────────────────┐
│ IDENTITIES & DEVICES │
Workforce │ Partners │ Citizens/Customers │ Service Accounts │ IoT/OT │
IdP/SSO/MFA UEM/MDM posture EDR/XDR health Certs/PKI/MTLS Device IDs
└───────────┬───────────┬───────────┬────────────┘
│ │ │
▼ ▼ ▼
┌──────────────────────────────────────────────────┐
│ SASE / SSE EDGE (GLOBAL POP MESH) │
│ ▸ ZTNA (app-level) ▸ SWG (web gateways) │
│ ▸ CASB (SaaS ctrl) ▸ FWaaS (L3–L7) │
│ ▸ DLP (inline/API) ▸ RBI/DNSsec/EmailSec │
│ ▸ Geo/Data Residency ▸ Policy/Governance bus │
└──────────────┬─────────────────────────┬─────────┘
│ │
▼ ▼
┌────────────────────────────────┐ ┌────────────────────────────────┐
│ PRIVATE APPS & NETWORKS │ │ CLOUD / SAAS DESTINATIONS │
│ • DC/Colo apps (mTLS/ZTNA) │ │ • IaaS/PaaS (DX/ER/GCI) │
│ • Segment gateways/SD-WAN │ │ • SaaS (CASB/API controls) │
└─────────────────┬──────────────┘ └──────────────┬─────────────────┘
│ │
▼ ▼
┌──────────────────────────┐ ┌─────────────────────────────┐
│ SEGMENTED NETWORK FABRIC │ │ DATA SERVICES / KEYS │
│ VRFs/VLANs microsegm. │ │ HSM/KMS/PKI Tokenization │
│ OT/PCI/PHI enclaves │ │ Pseudonymize/Masking/DLP │
└──────────────────────────┘ └─────────────────────────────┘
Telemetry/Controls ──► SIEM/SOAR AIOps/Observability ITSM/CMDB GRC/Audit (WORM)
Admin Access ────────► PAM/JIT (recorded, time-boxed sessions, policy-as-code)
Narrative (the policy-perimeter that protects every domain)
1) Purpose & posture
- Objective: Provide a unified, global zero-trust perimeter that consistently controls who/what can access which app/data, from where, on which device, under which conditions—across all 14 domain architectures and the control plane.
- Posture: Identity-first, device-aware, least-privilege, data-centric, and jurisdiction-aware (geo/data residency).
2) Identity, device, and session (syntax of admission)
- IdP/SSO/MFA: users, partners, and service accounts authenticate with adaptive factors.
- UEM/MDM + EDR/XDR: device posture (OS, patch, disk crypto, sensor health) becomes a policy signal.
- Certificates/PKI/MTLS: apps/services/IoT identify themselves cryptographically; no implicit trust.
3) SASE/SSE POP mesh (semantics enforced in-line)
- ZTNA: per-app access with context (user, device, location, risk score).
- SWG: governs web egress with URL categories, file controls, anti-malware.
- CASB: controls SaaS (inline + API) for sharing, external collaborators, OAuth risk.
- FWaaS: L3–L7 policy at the edge; micro-tunnels to segmented networks.
- DLP: inline and API-mode classifiers prevent PHI/PCI/PII leaks; tokenization/masking where needed.
- RBI/DNS/Email security: isolates browsing; blocks brand abuse and BEC.
- Geo/Data-residency: policies pin sessions & storage to lawful regions (e.g., EU-only).
4) Reaching private apps & segmented networks
- ZTNA connectors publish DC/Colo and VPC apps without inbound exposure; mTLS between connector and POP.
- SD-WAN/segment gateways stitch to VRFs/VLANs/enclaves (PCI, PHI, OT), maintaining microsegmentation end-to-end.
5) Data, keys, and secrets (meaning with custody)
- HSM/KMS/PKI: centralized key custody, rotation, and envelope encryption; crypto-erasure procedures codified.
- Data services provide tokenization, masking, pseudonymization, guarded by DLP and policy-as-code.
6) Admin, ops, and evidence (pragmatics of trust)
- PAM/JIT: privileged sessions are time-boxed, recorded, and policy-approved; credentials vaulted and rotated.
- SIEM/SOAR & AIOps: every edge decision, alert, and session is correlated; playbooks isolate VRFs, revoke tokens, rotate keys, and open ITSM incidents with CMDB context.
- GRC/Audit: controls mapped to frameworks (PCI, HIPAA, NERC, CJIS, ISO, SOC2, GDPR); logs/evidence into WORM storage for provable compliance.
7) Resilience & scale
- POP mesh: anycast onboarding, multi-region HA; session migration during POP failover.
- Policy distribution: config as code, signed and versioned; roll-forward/rollback with drift detection.
- Capacity: autoscale at POPs; per-tenant rate limits protect service quality.
8) Reference KPIs
- Auth success to app permit: <2 s median
- POP availability: ≥99.999% • Policy drift: 0 critical
- DLP efficacy: <0.1% false negatives on protected classes (tuned per domain)
- Incident MTTR (access containment): ≤1 h
9) Minimal BOM (cross-domain)
IdP/SSO/MFA, UEM/MDM, EDR/XDR, ZTNA, SWG, CASB, FWaaS, DLP (inline/API), RBI, DNS/Email security, ZT connectors, Segment gateways/SD-WAN, HSM/KMS/PKI, PAM/JIT, SIEM/SOAR, AIOps/Observability, ITSM/CMDB, GRC + WORM audit store.