Skip to main content

infrastructureVersion 1SOC2ISO27001NIST800-171

Network Security Policy

Edge, WAF, segmentation, and administrative access for Rex Black networks.

Download PDFSHA-256 029bf167df64e9d7…

Network Security Policy

1. Purpose

Protects the network paths into and within Rex Black's cloud and endpoints.

2. Internet-facing

  1. All traffic to Rex Black services ingresses through AWS CloudFront (CDN) and/or the application load balancer with AWS WAF enabled.
  2. WAF rule sets:
    • AWS managed Core Rule Set.
    • AWS managed Known Bad Inputs.
    • Rate limiting per IP for authentication endpoints.
    • Bot control for public APIs.
  3. DDoS protection: AWS Shield Standard for all endpoints; Shield Advanced for high-risk customer-facing endpoints when justified.

3. Internal

  1. Lambdas that need VPC-internal access run inside a private VPC subnet; public subnets are used only for NAT/ALB.
  2. Security groups use least-privilege ingress rules; default is "deny all, allow explicit".
  3. Egress is denied by default; allow-lists are configured per service.
  4. No inbound SSH/RDP to any production host. Administration is via AWS SSM Session Manager, audited and time-boxed.

4. Endpoints

  1. Endpoints connect to Rex Black services over TLS; local firewall enabled; no inbound ports open to hostile networks.
  2. Work over public Wi-Fi to Restricted data requires an approved VPN (014-remote-work-policy.md).

5. DNS

  1. DNS is authoritative in Route 53; DNSSEC enabled on public zones.
  2. Outbound DNS from AWS workloads uses Route 53 Resolver; suspicious domains are blocked by a DNS firewall rule set.

6. Segmentation

  1. Non-production environments (dev, staging) are logically separated from production by account or VPC boundary and cannot reach production data stores.
  2. Break-glass network paths (Security Officer only) are documented and alert on use.

7. Change control

Network and WAF changes follow the Change Management Policy and require Security Officer review.

8. Roles & responsibilities

Role Responsibility
Security Officer Owns network architecture and WAF tuning.
Engineering Implements least-privilege security groups and IaC.

9. References

  • 011-encryption-standard.md
  • 014-remote-work-policy.md
  • 021-logging-and-monitoring-policy.md

10. Revision history

Version Date Author Approver Change
1.0 2026-04-17 S.O. CEO Initial policy

Approval

This policy has been reviewed and is hereby approved for the named version and effective date above.

Approved by Myles Bai
Title Chief Executive Officer, Rex Black LLC
Email myles@rexblack.com
Approval date 2026-04-17
Effective date 2026-04-17
Next review due 2027-04-17

Digital signature of record: the CEO's electronic approval is captured in the platform audit log (event kind admin.policy.approved) with hash-chained integrity under the M-C1 control. The hash-chained audit log entry for this document is the canonical signature of record; this printed block exists for print/review convenience.

← Back to the trust center