Architecture 16 — Global Zero-Trust Access Fabric (SASE/SSE)

Reference Architecture Diagram + Narrative (policy-driven perimeter for everything)

                       ┌──────────────────────────────────────────────┐
                       │            IDENTITIES & DEVICES              │
  Workforce │ Partners │ Citizens/Customers │ Service Accounts │ IoT/OT │
  IdP/SSO/MFA  UEM/MDM posture  EDR/XDR health  Certs/PKI/MTLS  Device IDs
                       └───────────┬───────────┬───────────┬────────────┘
                                   │           │           │
                                   ▼           ▼           ▼
                  ┌──────────────────────────────────────────────────┐
                  │        SASE / SSE EDGE (GLOBAL POP MESH)         │
                  │  ▸ ZTNA (app-level)   ▸ SWG (web gateways)       │
                  │  ▸ CASB (SaaS ctrl)   ▸ FWaaS (L3–L7)            │
                  │  ▸ DLP (inline/API)   ▸ RBI/DNSsec/EmailSec      │
                  │  ▸ Geo/Data Residency   ▸ Policy/Governance bus  │
                  └──────────────┬─────────────────────────┬─────────┘
                                 │                         │
                                 ▼                         ▼
      ┌────────────────────────────────┐     ┌────────────────────────────────┐
      │ PRIVATE APPS & NETWORKS        │     │  CLOUD / SAAS DESTINATIONS     │
      │  • DC/Colo apps (mTLS/ZTNA)    │     │  • IaaS/PaaS (DX/ER/GCI)       │
      │  • Segment gateways/SD-WAN     │     │  • SaaS (CASB/API controls)    │
      └─────────────────┬──────────────┘     └──────────────┬─────────────────┘
                        │                                     │
                        ▼                                     ▼
         ┌──────────────────────────┐         ┌─────────────────────────────┐
         │ SEGMENTED NETWORK FABRIC │         │   DATA SERVICES / KEYS      │
         │  VRFs/VLANs  microsegm.  │         │  HSM/KMS/PKI  Tokenization  │
         │  OT/PCI/PHI enclaves     │         │  Pseudonymize/Masking/DLP   │
         └──────────────────────────┘         └─────────────────────────────┘

   Telemetry/Controls ──► SIEM/SOAR  AIOps/Observability  ITSM/CMDB  GRC/Audit (WORM)
   Admin Access ────────► PAM/JIT  (recorded, time-boxed sessions, policy-as-code)

Narrative (the policy-perimeter that protects every domain)

1) Purpose & posture

  • Objective: Provide a unified, global zero-trust perimeter that consistently controls who/what can access which app/data, from where, on which device, under which conditions—across all 14 domain architectures and the control plane.
  • Posture: Identity-first, device-aware, least-privilege, data-centric, and jurisdiction-aware (geo/data residency).

2) Identity, device, and session (syntax of admission)

  • IdP/SSO/MFA: users, partners, and service accounts authenticate with adaptive factors.
  • UEM/MDM + EDR/XDR: device posture (OS, patch, disk crypto, sensor health) becomes a policy signal.
  • Certificates/PKI/MTLS: apps/services/IoT identify themselves cryptographically; no implicit trust.

3) SASE/SSE POP mesh (semantics enforced in-line)

  • ZTNA: per-app access with context (user, device, location, risk score).
  • SWG: governs web egress with URL categories, file controls, anti-malware.
  • CASB: controls SaaS (inline + API) for sharing, external collaborators, OAuth risk.
  • FWaaS: L3–L7 policy at the edge; micro-tunnels to segmented networks.
  • DLP: inline and API-mode classifiers prevent PHI/PCI/PII leaks; tokenization/masking where needed.
  • RBI/DNS/Email security: isolates browsing; blocks brand abuse and BEC.
  • Geo/Data-residency: policies pin sessions & storage to lawful regions (e.g., EU-only).

4) Reaching private apps & segmented networks

  • ZTNA connectors publish DC/Colo and VPC apps without inbound exposure; mTLS between connector and POP.
  • SD-WAN/segment gateways stitch to VRFs/VLANs/enclaves (PCI, PHI, OT), maintaining microsegmentation end-to-end.

5) Data, keys, and secrets (meaning with custody)

  • HSM/KMS/PKI: centralized key custody, rotation, and envelope encryption; crypto-erasure procedures codified.
  • Data services provide tokenization, masking, pseudonymization, guarded by DLP and policy-as-code.

6) Admin, ops, and evidence (pragmatics of trust)

  • PAM/JIT: privileged sessions are time-boxed, recorded, and policy-approved; credentials vaulted and rotated.
  • SIEM/SOAR & AIOps: every edge decision, alert, and session is correlated; playbooks isolate VRFs, revoke tokens, rotate keys, and open ITSM incidents with CMDB context.
  • GRC/Audit: controls mapped to frameworks (PCI, HIPAA, NERC, CJIS, ISO, SOC2, GDPR); logs/evidence into WORM storage for provable compliance.

7) Resilience & scale

  • POP mesh: anycast onboarding, multi-region HA; session migration during POP failover.
  • Policy distribution: config as code, signed and versioned; roll-forward/rollback with drift detection.
  • Capacity: autoscale at POPs; per-tenant rate limits protect service quality.

8) Reference KPIs

  • Auth success to app permit: <2 s median
  • POP availability: ≥99.999% • Policy drift: 0 critical
  • DLP efficacy: <0.1% false negatives on protected classes (tuned per domain)
  • Incident MTTR (access containment): ≤1 h

9) Minimal BOM (cross-domain)

IdP/SSO/MFA, UEM/MDM, EDR/XDR, ZTNA, SWG, CASB, FWaaS, DLP (inline/API), RBI, DNS/Email security, ZT connectors, Segment gateways/SD-WAN, HSM/KMS/PKI, PAM/JIT, SIEM/SOAR, AIOps/Observability, ITSM/CMDB, GRC + WORM audit store.