ietf-wg-scitt / draft-ietf-scitt-software-use-cases

Other
0 stars 5 forks source link

Air-gap or network isolated network references #2

Open SteveLasker opened 10 months ago

SteveLasker commented 10 months ago

Section 3.7. Authentic Software Components in Air-Gapped Infrastructure uses the term "air-gapped" and "off-line". While "air-gapped" is a common term, it's often used to refer to highly isolated environments. While users are embracing cloud environments, they still wish to maintain network isolation, through virtual private networks. Can/should we reword this section to refer to the more common network isolated environments? The subtle difference between network-isolated and air-gapped is a network-isolated environment may enable ingress/egress rules while an air-gapped environment may implement a data-diode that allows content to go into an environment but the environment can never reach out. (diode = one-way)

OR13 commented 9 months ago

It seems worth while to address the isolation levels since each might have different challenges: