COS-02—Security requirements for connections in the Cloud Service Provider's network
>Control Description
Specific security requirements are designed, published and provided for establishing connections within the Cloud Service Provider's network. The security requirements define for the Cloud Service Provider's area of responsibility:
• in which cases the security zones are to be separated and in which cases cloud customers are to be logically or physically segregated;
• which communication relationships and which network and application protocols are permitted in each case;
• how the data traffic for administration and monitoring is segregated from each on network level;
• which internal, cross-location communication is permitted and;
• which cross-network communication is allowed
Additional criteria: -
Ask AI
Configure your API key to use AI features.