infrastructureVersion 1SOC2ISO27001NIST800-171
Network Security Policy
Edge, WAF, segmentation, and administrative access for Rex Black networks.
Download PDFSHA-256 029bf167df64e9d7…
Network Security Policy
1. Purpose
Protects the network paths into and within Rex Black's cloud and endpoints.
2. Internet-facing
- All traffic to Rex Black services ingresses through AWS CloudFront (CDN) and/or the application load balancer with AWS WAF enabled.
- WAF rule sets:
- AWS managed Core Rule Set.
- AWS managed Known Bad Inputs.
- Rate limiting per IP for authentication endpoints.
- Bot control for public APIs.
- DDoS protection: AWS Shield Standard for all endpoints; Shield Advanced for high-risk customer-facing endpoints when justified.
3. Internal
- Lambdas that need VPC-internal access run inside a private VPC subnet; public subnets are used only for NAT/ALB.
- Security groups use least-privilege ingress rules; default is "deny all, allow explicit".
- Egress is denied by default; allow-lists are configured per service.
- No inbound SSH/RDP to any production host. Administration is via AWS SSM Session Manager, audited and time-boxed.
4. Endpoints
- Endpoints connect to Rex Black services over TLS; local firewall enabled; no inbound ports open to hostile networks.
- Work over public Wi-Fi to Restricted data requires an approved
VPN (
014-remote-work-policy.md).
5. DNS
- DNS is authoritative in Route 53; DNSSEC enabled on public zones.
- Outbound DNS from AWS workloads uses Route 53 Resolver; suspicious domains are blocked by a DNS firewall rule set.
6. Segmentation
- Non-production environments (
dev,staging) are logically separated from production by account or VPC boundary and cannot reach production data stores. - Break-glass network paths (Security Officer only) are documented and alert on use.
7. Change control
Network and WAF changes follow the Change Management Policy and require Security Officer review.
8. Roles & responsibilities
| Role | Responsibility |
|---|---|
| Security Officer | Owns network architecture and WAF tuning. |
| Engineering | Implements least-privilege security groups and IaC. |
9. References
011-encryption-standard.md014-remote-work-policy.md021-logging-and-monitoring-policy.md
10. Revision history
| Version | Date | Author | Approver | Change |
|---|---|---|---|---|
| 1.0 | 2026-04-17 | S.O. | CEO | Initial policy |
Approval
This policy has been reviewed and is hereby approved for the named version and effective date above.
| Approved by | Myles Bai |
| Title | Chief Executive Officer, Rex Black LLC |
| myles@rexblack.com | |
| Approval date | 2026-04-17 |
| Effective date | 2026-04-17 |
| Next review due | 2027-04-17 |
Digital signature of record: the CEO's electronic approval is captured
in the platform audit log (event kind admin.policy.approved) with
hash-chained integrity under the M-C1 control. The hash-chained audit
log entry for this document is the canonical signature of record; this
printed block exists for print/review convenience.