4.2 Current IT architecture
This section provides background information about the existing Armando
Banking Brothers Company IT architecture, including the network infrastructure,
security infrastructure, and the middleware/application infrastructure.
4.2.1 Network infrastructure
Next we describe the logical network components that make up the ABBC
network (Figure 4-1). ABBC has developed the network and application security
infrastructure in line with the IBM MASS security model. The network has the
following major security zones:
Uncontrolled zone/Internet, external networks
Controlled zone/demilitarized zone (DMZ)
Controlled/intranet
Restricted/production network
Restricted/management network
Dialup
Client
Branch
Office
Internet
VPN
Client
Partner
WAN
External Network
Figure 4-1 ABBC current network diagram
DMZ –2
VPN & R-access
DMZ –1
Server
DMZ –3
Ext network
DMZ
LAN
Branch
Office
WAN
Core
LAN
LAB
Intranet
Virtual Private
network
Wireless
Access point
Chapter 4. Armando Banking Brothers Corporation
Production
Network
TCM
Production
Compliance
Servers
& Remediation
NMS
ACS
Management
Network
Intrusion detection
Firewall
System
Router
SCM
79