One policy, and the places it has to hold
- The branch that got its own firewall
- Bought in a hurry by whoever was on site, configured by whoever was available, and never compared against the rules at head office. It is one estate or it is a list of exceptions, and the second one is only discovered during an incident.
- The lift-and-shift
- A workload moved to the cloud keeps the ruleset it had in the rack, and the rack had a perimeter around it. What protected it there does not exist there, and the gap is usually found by somebody enumerating it.
- The contractor’s laptop
- Not your build, not your patch cycle, and on your network by Tuesday. Access decided by who the user is and what the device is currently in a state to be trusted with, rather than by which cable it is plugged into.
- The exception nobody removed
- Opened for a migration in March, still open in November because the person who asked for it has left and nobody is certain what breaks if it closes. One policy means one place to find it and one place to answer for it.
- The audit
- Somebody asks what the rule is for remote access to production. With three estates that is three answers and a week of reconciliation. With one it is a screen.
- The new office
- The question is how long until it is protected the same way as the others. The policy already exists; what is left is applying it, which is the difference between an estate and a collection.