ข้ามไปยังเนื้อหา

CISSP Domain 4: Communication and Network Security

Domain 4 ว่าด้วยการออกแบบและป้องกันเส้นทางที่ข้อมูล ระบบ และผู้ใช้สื่อสารกัน ตั้งแต่สายสัญญาณ frame, packet และ session ไปจนถึง Virtual Private Network (VPN), wireless, Software-Defined Networking (SDN) และ cloud networking เป้าหมายไม่ใช่เพียงทำให้ packet ไปถึงปลายทาง แต่ต้องทำให้การสื่อสารสอดคล้องกับ classification, business requirement, trust boundary และ risk decision ขององค์กร

หลักคิดสำหรับข้อสอบ: เริ่มจาก data flow และ security requirement ก่อนเลือก protocol หรืออุปกรณ์ ใช้ segmentation จำกัด blast radius, ใช้ secure protocol ปกป้องข้อมูลระหว่างทาง และอย่าถือว่า network location เพียงอย่างเดียวทำให้ subject น่าเชื่อถือ

ตาม CISSP Certification Exam Outline ของ ISC2 Domain 4 มีน้ำหนักเฉลี่ย 13% ของข้อสอบ เนื้อหาหลักแบ่งได้เป็นสามกลุ่ม ได้แก่ การใช้ secure design principles กับ network architecture, การรักษาความปลอดภัยของ network components และการนำ secure communication channel ไปใช้ตาม design

คำว่า “น้ำหนักเฉลี่ย” ใช้สำหรับวางแผนอ่าน ไม่รับประกันจำนวนข้อของผู้สอบแต่ละคน ข้อสอบมักไม่ถามเพียงว่า protocol ทำงานที่ port ใด แต่ให้สถานการณ์ที่ต้องแยก requirement ออกจาก implementation เช่น ต้องปกป้อง data in transit ระหว่างสอง site, จำกัด lateral movement หลัง endpoint ถูกยึด หรือทำให้ remote administrator เข้าถึง management plane อย่างตรวจสอบย้อนหลังได้

ความสามารถสำคัญของ Domain นี้ประกอบด้วย

  1. อ่าน network เป็นชั้นและเป็น flow ใช้ Open Systems Interconnection (OSI) และ TCP/IP models เพื่อระบุตำแหน่งของ protocol, control, encapsulation และ failure
  2. ออกแบบ boundary และ segmentation แยก zone ตาม sensitivity, function และ trust requirement โดยมี policy ควบคุม traffic ระหว่าง zone
  3. เลือก preventive และ detective controls เข้าใจ firewall, proxy, Network Access Control (NAC), Intrusion Detection System (IDS), Intrusion Prevention System (IPS) และ telemetry โดยไม่คาดหวังว่า control เดียวจะหยุดทุก threat
  4. สร้าง secure communication channel เลือก Internet Protocol Security (IPsec), Transport Layer Security (TLS), Secure Shell (SSH) หรือกลไกอื่นให้ตรง use case พร้อม authentication, key establishment และ certificate validation
  5. รักษา modern network ประเมิน wireless, SDN, virtual network, cloud, container, hybrid connection และ third-party connectivity ภายใต้ shared responsibility

Domain 4 รับ classification และ handling requirement จาก Domain 2 และรับ trust boundary, cryptographic service, resilience requirement จาก Domain 3 Network architect เลือก topology, protocol และ control ส่วน Data owner, System owner และ Risk owner ยังคงกำหนด requirement และยอมรับ residual risk ตาม authority ของตน

Data flow อธิบายว่า data ชนิดใดเคลื่อนจาก source ใด ไป destination ใด ผ่าน protocol, interface, intermediary และ trust boundary อะไรบ้าง การวาดเพียง server กับ firewall แต่ไม่แสดง identity, direction, port, dependency, management path และ data classification ทำให้ประเมิน risk ได้ไม่ครบ

แต่ละ flow ควรตอบคำถามอย่างน้อยว่าใครเริ่ม connection, ใคร authenticate ใคร, ต้องรักษา Confidentiality หรือ Integrity ระดับใด, ยอมให้ latency และ outage เท่าใด, log ที่จุดใด และใครอนุมัติ flow นั้น ตัวอย่างเช่น “application ติดต่อ database” ยังไม่พอ ต้องรู้ว่าใช้ service identity ใด ผ่าน TLS หรือไม่ จำกัดเฉพาะ query service หรือเปิด administrative interface และมีเส้นทาง bypass หรือไม่

2.2 Layering ช่วยวิเคราะห์ แต่ attacker ไม่เคารพขอบเขตของ model

หัวข้อที่มีชื่อว่า “2.2 Layering ช่วยวิเคราะห์ แต่ attacker ไม่เคารพขอบเขตของ model”

OSI และ TCP/IP เป็น conceptual models ช่วยจัดระเบียบหน้าที่ของ protocol และหาจุดวาง control ปัญหาหนึ่งอาจเกิดและถูกสังเกตได้หลายชั้น เช่น Distributed Denial-of-Service (DDoS) อาจทำให้ link เต็มที่ lower layer, ใช้ TCP state จน firewall หมดทรัพยากร หรือส่ง HTTP request ที่แพงต่อ application

Encapsulation คือการที่ชั้นหนึ่งห่อข้อมูลจากชั้นบนด้วย header หรือ trailer ของตน เมื่อใช้ tunnel จะเกิด packet ซ้อน packet เพิ่มอีกชั้น การวิเคราะห์เฉพาะ outer header อาจมองไม่เห็น payload ด้านใน ขณะที่การถอด TLS เพื่อ inspection เพิ่ม privacy, key custody, capacity และ legal considerations แนวคิดนี้เรียกว่า multilayer protocol implications: control ที่เห็นเพียงชั้นหนึ่งอาจตัดสินใจผิดเมื่อข้อมูลสำคัญอยู่คนละชั้น

Network segmentation แบ่ง network ออกเป็นส่วนตาม business function, sensitivity, environment หรือ trust requirement เป้าหมายคือจำกัด reachability, ลด lateral movement และทำให้ policy ตรวจสอบได้ การแบ่ง subnet หรือ Virtual Local Area Network (VLAN) อย่างเดียวไม่ใช่ security boundary หาก routing ระหว่าง segment เปิดกว้าง

Boundary ต้องมี enforcement เช่น firewall, router Access Control List (ACL), security group, host firewall, service mesh policy หรือ gateway พร้อม default-deny ตามความเหมาะสม Microsegmentation เพิ่ม policy ที่ละเอียดถึง workload, application หรือ identity และเหมาะกับ east-west traffic ที่ perimeter firewall มองไม่เห็น แต่ความละเอียดสูงทำให้ dependency mapping และ policy lifecycle ยากขึ้น

แนวคิด Zero Trust Architecture (ZTA) ไม่ให้ implicit trust เพียงเพราะ request มาจาก “เครือข่ายภายใน” การตัดสินใจควรพิจารณา identity, device state, requested resource, context, risk และ policy พร้อมบันทึก telemetry หลักนี้ไม่แปลว่าไม่เชื่อใครเลย และไม่ใช่ผลิตภัณฑ์ชนิดหนึ่ง

Network location ยังใช้เป็น risk signal และจุด enforcement ได้ แต่ไม่ควรเป็นหลักฐานเดียวว่า request ได้รับอนุญาต ตัวอย่างเช่น administrator ที่อยู่ใน corporate LAN ยังต้องใช้ Multi-Factor Authentication (MFA), privileged device, approved management path และ session logging

Firewall ลด traffic ที่ไม่อนุญาต แต่ไม่ยืนยันว่า traffic ที่อนุญาตไม่มี exploit IDS อาจตรวจพบ pattern ที่น่าสงสัยแต่ไม่หยุด packet IPS อาจ block ได้แต่เสี่ยง false positive กระทบ Availability ส่วน encryption ปกป้อง payload จากผู้ดักฟัง แต่ทำให้ passive sensor มองเห็นเนื้อหาน้อยลง

จึงต้องออกแบบ control เป็นระบบ: ลด attack surface, authenticate peer, encrypt channel, filter flow, ตรวจ anomaly, เก็บ log, correlate event และมี response playbook หลักฐานจาก firewall, DNS, proxy, endpoint และ cloud flow logs ต้องมีเวลาอ้างอิงที่สอดคล้องกัน มิฉะนั้นการสืบเหตุจะต่อ timeline ได้ยาก

Network resilience ไม่ได้เกิดจากมี link สำรองเพียงเส้นเดียว ต้องพิจารณา power, device, route, DNS, certificate, identity provider, cloud gateway, carrier และ configuration plane ที่อาจเป็น shared dependency Redundancy ที่อยู่ใน failure domain เดียวกัน เช่น circuit สองเส้นผ่านท่อเดียวกัน อาจล้มพร้อมกัน

High availability ต้องกำหนด failure mode, failover trigger, state synchronization, capacity และการทดสอบ หาก firewall pair สลับเครื่องได้แต่ session state หาย application อาจยังหยุดชะงัก Load balancer ช่วยกระจาย connection และ health check backend แต่ไม่แทน capacity planning, DDoS protection หรือ application resilience

OSI model มีเจ็ดชั้น ส่วน TCP/IP model ที่ใช้งานทั่วไปมักสรุปเป็นสี่ชั้น การจับคู่เป็นการประมาณเพื่อช่วยคิด ไม่ใช่ความสัมพันธ์แบบหนึ่งต่อหนึ่งที่ทุกตำราใช้เหมือนกัน

OSI layerหน้าที่และตัวอย่างTCP/IP โดยประมาณSecurity concern และ control ตัวอย่าง
7 ApplicationHTTP, DNS, SMTP, SSH, API semanticsApplicationauthentication, input validation, WAF, secure protocol, application log
6 Presentationencoding, serialization, compression, encryption representationApplicationunsafe parser, downgrade, certificate/cryptographic configuration
5 Sessionสร้าง รักษา และยุติ dialogue/sessionApplicationsession hijacking, replay, timeout, reauthentication
4 TransportTCP/UDP, port, reliability, flow controlTransportport filtering, SYN flood, state exhaustion, TLS above transport
3 NetworkIPv4/IPv6, routing, ICMP, logical addressingInternetspoofing, route manipulation, ACL, IPsec, anti-spoofing
2 Data LinkEthernet frame, MAC, VLAN, switching, Wi-Fi framingLink/Network accessARP spoofing, VLAN hopping, port security, 802.1X
1 Physicalcopper, fiber, radio, connector, signalLink/Network accesstapping, jamming, cable cut, locked facility, diverse path

ตัวอย่างการแก้ปัญหา: ผู้ใช้ resolve ชื่อได้และ ping server ได้ แต่ HTTPS ใช้ไม่ได้ แสดงว่า lower layers บางส่วนทำงานแล้ว ควรตรวจ TCP connection, TLS handshake, certificate, proxy และ application ต่อ ไม่ควรสรุปว่า “network ปกติ” เพียงเพราะ ICMP ตอบ

Transmission Control Protocol (TCP) เป็น connection-oriented transport มี sequence, acknowledgement, retransmission และ flow control การเริ่ม connection ปกติใช้ three-way handshake: SYN, SYN-ACK, ACK คุณสมบัตินี้ช่วยส่งข้อมูลเชื่อถือได้ แต่สร้าง state ที่ถูกใช้โจมตีแบบ SYN flood หรือ state exhaustion ได้

User Datagram Protocol (UDP) เป็น connectionless และไม่มี reliability, ordering หรือ congestion behavior แบบ TCP ในตัว จึงมี overhead ต่ำและเหมาะกับ use case เช่น DNS query, streaming หรือ real-time traffic บางแบบ แต่ application ต้องจัดการ reliability และ security ที่ต้องการเอง UDP ไม่ได้ “ไม่ปลอดภัย” โดยธรรมชาติ และ TCP ไม่ได้ “ปลอดภัย” เพียงเพราะมี handshake

Port ระบุ service endpoint เชิงตรรกะ ไม่ใช่หลักฐานว่า application เป็น service ตามชื่อที่คาด Malware ใช้ TCP 443 ได้ และ HTTPS อาจอยู่ port อื่น Firewall ที่อนุญาตจาก port number อย่างเดียวจึงต้องทำงานร่วมกับ application awareness, identity และ monitoring ตาม risk

IPv4 ใช้ address 32 bits ส่วน IPv6 ใช้ 128 bits IPv4 มี unicast, broadcast และ multicast; IPv6 ไม่มี broadcast และใช้ multicast รวมถึง anycast Anycast ให้หลาย node ประกาศ address เดียวกัน แล้ว routing เลือก instance ตามเส้นทาง

Network Address Translation (NAT) แปลง address และบางกรณีแปลง port เพื่อประหยัด IPv4 address หรือเชื่อม address domains NAT ไม่ใช่ security control ทดแทน firewall แม้การแปล address อาจทำให้ inbound connection บางแบบเข้าถึงไม่ได้โดยค่าเริ่มต้น IPv6 ทำให้ต้องทบทวน policy, asset inventory, Neighbor Discovery, router advertisement และ monitoring แทนการพึ่ง NAT เป็นสมมติฐานการป้องกัน

ที่ Layer 2 switch ส่ง frame ตาม MAC address และแบ่ง broadcast domain ด้วย VLAN ที่ Layer 3 router ส่ง packet ระหว่าง network ตาม routing table การกำหนด VLAN ต้องป้องกัน trunk ที่ไม่จำเป็น, unused port, native VLAN confusion และ management interface แต่ VLAN ไม่ใช่ cryptographic isolation และ configuration ผิดอาจเปิดทาง VLAN hopping

Address Resolution Protocol (ARP) จับคู่ IPv4 address กับ MAC address ใน local segment และไม่มี authentication โดยกำเนิด จึงเกิด ARP spoofing ได้ IPv6 ใช้ Neighbor Discovery Protocol (NDP) ซึ่งมี threat ของตน Control ใช้ switch features, segmentation และ monitoring ตาม platform Routing protocol ต้องป้องกัน route injection/hijacking ด้วย peer authentication เมื่อรองรับ, route filtering, change control และ monitoring

  • Data plane หรือ forwarding plane ส่ง traffic ของผู้ใช้ตาม forwarding decision
  • Control plane เรียนรู้ topology และสร้าง decision เช่น route หรือ forwarding state
  • Management plane ใช้ configure, monitor และ administer อุปกรณ์

ทั้งสาม plane ต้องแยก policy และลด reachability โดยเฉพาะ management plane ควรใช้ dedicated management network หรือ out-of-band path เมื่อ requirement เหมาะสม พร้อม strong authentication, encrypted administration, role-based access, logging และ break-glass process หาก attacker ควบคุม management plane ได้ เขาอาจเปลี่ยน policy ทั้งระบบแม้ data-plane filtering เดิมถูกต้อง

ภาพนี้แสดงว่าแต่ละ plane มีหน้าที่ต่างกัน แต่การเปลี่ยนผ่าน management plane สามารถส่งผลต่อ decision และการ forward traffic ได้:

flowchart LR admin["Administrator / management service"] --> mgmt["Management plane: configure, monitor, administer"] mgmt -->|"Configuration / policy"| ctrl["Control plane: learn topology and create decision"] ctrl -->|"Routing / forwarding decision"| data["Data plane: forward user traffic"] mgmt -->|"Configuration / policy"| data source["User traffic"] --> data --> dest["Destination"]

การเลือกว่า protocol “secure” ต้องดูมากกว่ามี encryption Channel ที่ดีควรให้ peer authentication, Confidentiality, Integrity, replay protection และ key establishment ตาม use case พร้อม algorithm และ certificate validation ที่องค์กรอนุมัติ

Use caseทางเลือกที่ควรหลีกเลี่ยงสำหรับข้อมูลสำคัญทางเลือกที่ปลอดภัยกว่าประเด็นตรวจสอบ
Remote shell/adminTelnet, rloginSSHhost key validation, MFA, key lifecycle, command/session logging
Web/APIHTTPHTTPS ด้วย TLShostname, trust chain, version/cipher policy, mutual TLS เมื่อจำเป็น
File transferFTP, TFTPSFTP, SCP หรือ FTPS ตาม requirementอย่าสับสน SFTP กับ FTPS; จำกัด path และ account
E-mail access/relayplaintext POP3/IMAP/SMTPTLS-protected channel ตาม roleSTARTTLS downgrade risk, server authentication, mail-layer protection
Network managementSNMPv1/v2c community stringSNMPv3 security featuresauthentication, privacy, least privilege, trap destination
Name resolutionDNS ปกติDNSSEC สำหรับ origin authenticity/integrity; encrypted DNS สำหรับ channel privacyสองกลไกแก้คนละปัญหา
Time synchronizationunauthenticated timeauthenticated/protected time source ตาม platformhierarchy, trusted source, monitoring, effect ต่อ log/certificate

TLS ทำงานเหนือ reliable transport ใน use case ทั่วไปและใช้ certificate หรือกลไกอื่น authenticate peer ตาม configuration การมีรูปกุญแจไม่ได้รับประกันว่า peer ถูกต้องหาก client ไม่ตรวจ hostname, chain หรือ trust anchor Mutual TLS (mTLS) ให้ทั้งสองฝั่งแสดง certificate แต่ authorization ยังต้องตัดสินว่าตัวตนนั้นเข้าถึง resource ใดได้

SSH ให้ encrypted channel สำหรับ remote administration, tunneling และ file transfer บางรูปแบบ จุดสำคัญคือ validate host key, ป้องกัน private key, จำกัด forwarding และไม่ใช้ shared administrator account หากผู้ใช้กดยอมรับ host key ที่เปลี่ยนโดยไม่ตรวจสอบ ก็อาจเปิดทาง Man-in-the-Middle (MITM)

DNSSEC ให้การตรวจ authenticity และ integrity ของ DNS data ผ่าน chain of trust ไม่ได้เข้ารหัสชื่อที่ query และไม่ได้รับประกันว่า destination ปลอดภัย ส่วน DNS over TLS (DoT) หรือ DNS over HTTPS (DoH) ปกป้อง channel ระหว่าง client กับ resolver แต่ไม่ได้แทน DNSSEC องค์กรต้องกำหนด resolver policy เพื่อไม่ให้ encrypted DNS กลายเป็นทาง bypass monitoring โดยไม่ได้ตั้งใจ

Dynamic Host Configuration Protocol (DHCP) แจก network configuration ให้ client แต่ server ปลอมอาจให้ gateway หรือ DNS ที่เป็นอันตราย Control เช่น authorized server, switch inspection feature และ NAC ช่วยลด risk ขณะที่ static address อย่างเดียวไม่ยืนยัน identity ของ device

Topology เชิงกายภาพบอกการเชื่อมสายและ device ส่วน logical topology บอก flow และ adjacency ที่ protocol เห็น แบบ star ดูแลง่ายแต่ central device อาจเป็น single point of failure ส่วน mesh มีหลายเส้นทางแต่ซับซ้อนกว่า

การแบ่ง network อาจใช้หลายระดับ

  • Physical segmentation ใช้อุปกรณ์หรือสื่อแยก เหมาะกับ requirement ที่ต้องการ isolation สูง แต่ยังมี shared facility, power หรือ administration ได้
  • Logical segmentation ใช้ VLAN, subnet, Virtual Routing and Forwarding (VRF), overlay หรือ virtual network พร้อม enforcement
  • DMZ เป็น zone สำหรับ service ที่ต้องติดต่อกับ network ต่าง trust level เช่น Internet-facing reverse proxy ไม่ใช่ synonym ของ “ปลอดภัย” และไม่ควรเปิด DMZ เข้าสู่ internal network แบบกว้าง
  • Microsegmentation กำหนด policy ระดับ workload หรือ identity ลด east-west movement ใน data center และ cloud
  • Air gap ตัดการเชื่อม network โดยตรง แต่ยังมี risk จาก removable media, maintenance laptop, radio, supply chain และ human procedure จึงไม่เท่ากับปลอดภัยสมบูรณ์

North-south traffic โดยทั่วไปหมายถึง traffic เข้าออก environment ส่วน east-west traffic หมายถึง traffic ระหว่าง workloads ภายใน ความหมายขึ้นกับ boundary ที่กำหนด Perimeter control มักเห็น north-south ดี แต่การโจมตีหลัง compromise ใช้ east-west path จึงต้องมี internal segmentation, endpoint telemetry และ identity-aware policy

ตัวอย่าง: ระบบชำระเงินอาจแบ่ง Internet edge, web tier, application tier, database tier และ management zone Firewall อนุญาต Internet ถึง reverse proxy บน HTTPS, proxy ถึง application เฉพาะ service port, application ถึง database ด้วย service identity และ encrypted channel ส่วน administration ผ่าน privileged access path เท่านั้น การเปิด “any-any ชั่วคราว” โดยไม่มี expiry และ owner ทำลายคุณค่าของ segmentation

ภาพนี้ถ่ายทอดตัวอย่างระบบชำระเงินข้างต้นให้เห็น zone และ enforcement ที่คั่นแต่ละ data flow:

flowchart LR client["Internet client"] -->|"HTTPS"| edgefw{"Edge enforcement"} subgraph edge["Internet edge / DMZ"] proxy["Reverse proxy"] end subgraph appzone["Application zone"] app["Application service"] end subgraph datazone["Database zone"] db["Database"] end edgefw --> proxy proxy -->|"Approved service port"| appfw{"Internal enforcement"} appfw --> app app -->|"Service identity + encrypted channel"| datafw{"Data-zone enforcement"} datafw --> db admin["Administrator"] -->|"Privileged access path"| mgmt["Management zone"]

การออกแบบ redundant path ต้องตรวจ route diversity, carrier independence, device, power, DNS, certificate และ capacity ระหว่าง failover ค่า Maximum Transmission Unit (MTU) ที่ต่างกันหรือ tunnel overhead อาจทำให้ packet fragmentation, black hole หรือ performance ลดลง การทดสอบ failover ต้องดู application transaction ไม่ใช่ดูเพียง link LED

Converged network ส่ง data, Voice over IP (VoIP), iSCSI storage หรือ industrial traffic บน infrastructure ร่วม จึงใช้ทรัพยากรได้ดีแต่ failure, congestion และ compromise มีผลกว้างขึ้น ต้องใช้ Quality of Service (QoS), segmentation, authentication, capacity และ resilience ตาม criticality QoS จัดลำดับ traffic แต่ไม่ใช่ security boundary และ storage VLAN อย่างเดียวไม่สร้าง Confidentiality

Firewall บังคับ policy ว่า traffic ใดผ่าน boundary ได้ตามข้อมูลที่มองเห็น ประเภทสำคัญมีดังนี้

ประเภทวิธีตัดสินหลักจุดเด่นข้อจำกัดสำคัญ
Packet-filtering/statelesssource/destination, protocol, port, directionเร็ว เรียบง่าย เหมาะกับ coarse filteringไม่เข้าใจ connection state หรือ application context มากนัก
Stateful inspectionติดตาม connection/state tableแยก established flow และ packet ผิด state ได้state exhaustion และ encrypted payload ยังเป็นข้อจำกัด
Circuit-level gatewayควบคุม session/circuitซ่อน internal connection detail บางส่วนมอง application content จำกัด
Application proxyยุติ connection แล้วสร้างอีกฝั่งในนาม clientตรวจ protocol และแยก connection ได้ลึกlatency, capacity, certificate และ compatibility complexity
Next-Generation Firewall (NGFW)state + application/user/content awarenesspolicy ละเอียดและรวม inspection หลายแบบต้อง tune, update และจัดการ encrypted traffic
Web Application Firewall (WAF)HTTP/application requestลด web attack บางแบบและใช้ virtual patching ได้ไม่แก้ business logic, broken authorization หรือ secure coding ทั้งหมด

Policy ที่ดีระบุ source, destination, service, direction, business owner, justification, expiry/review และ logging Default deny ลด unintended access แต่ต้องมี dependency discovery และ exception process การเรียง rule สำคัญ เพราะ broad allow ที่อยู่ก่อน specific deny อาจทำให้ deny ไม่เคยถูกใช้ตาม firewall semantics

Egress filtering จำกัด traffic ออกจาก network ช่วยลด command-and-control, data exfiltration และ spoofed traffic แต่ต้องไม่สมมติว่า outbound traffic ปลอดภัย Ingress filtering ลด traffic เข้ามาที่ไม่ควรเห็นจากแหล่งนั้น Anti-spoofing ควรใช้ใกล้ source และ boundary หลายจุดตาม architecture

Forward proxy ทำงานแทน client ที่ออกไปหา server ส่วน reverse proxy ทำงานหน้า server เพื่อรับ request จาก client ทั้งสองสามารถ enforce authentication, filtering, caching หรือ TLS policy ได้ต่างกัน Network Address Translation (NAT) แปล address; proxy ยุติและสร้าง application connection ใหม่ จึงไม่ใช่สิ่งเดียวกัน

Firewall placement ต้องสัมพันธ์กับ trust boundary เช่น Internet edge, partner connection, data center tier, cloud subnet, host และ management plane การมี firewall หลายชั้นแต่ใช้ rule any-any ชุดเดียวกันไม่ใช่ defense in depth ที่มีประสิทธิผล

Intrusion Detection System (IDS) วิเคราะห์ event หรือ traffic แล้วแจ้งเตือน ส่วน Intrusion Prevention System (IPS) อยู่ในตำแหน่งที่ block, reject หรือเปลี่ยน traffic ได้ IDS มักเป็น detective control; IPS มี preventive/corrective effect แต่ทั้งคู่ต้องมี sensor coverage, detection logic, tuning และ response owner

แบ่งตามตำแหน่งข้อมูลได้เป็น

  • Network-based IDS/IPS (NIDS/NIPS) เห็น traffic ที่จุดเครือข่าย เหมาะกับหลาย host แต่ visibility ลดลงเมื่อ traffic เข้ารหัสหรือ path ไม่ผ่าน sensor
  • Host-based IDS/IPS (HIDS/HIPS) เห็น process, file, system call และ traffic หลัง endpoint ถอดรหัสบางส่วน แต่ต้อง deploy และป้องกัน agent
  • Network Detection and Response (NDR) ใช้ network telemetry, metadata และ analytics เพื่อตรวจพฤติกรรมและช่วย response ไม่ได้ทำให้ signature หรือ human analysis หมดความจำเป็น

วิธีตรวจหลักคือ signature-based detection ซึ่งแม่นกับ pattern ที่รู้จักแต่พลาด variant ใหม่ และ anomaly/behavior-based detection ซึ่งหาความต่างจาก baseline แต่มี false positive หาก environment เปลี่ยน Rule-based หรือ protocol analysis ตรวจ violation ของ policy และ protocol semantics ได้อีกแบบ

False positive คือ alert เมื่อไม่มีเหตุร้าย ทำให้ analyst ล้า; false negative คือมีเหตุร้ายแต่ไม่ alert ทำให้เกิด blind spot Threshold ที่เข้มขึ้นอาจลด false negative แต่เพิ่ม false positive ไม่มีค่า sensitivity ที่ดีที่สุดสำหรับทุกระบบ ต้อง tune ตาม asset criticality, threat และ response capacity

ตำแหน่ง sensor เป็น design decision Sensor นอก edge firewall เห็น hostile traffic ปริมาณมากและช่วย threat research แต่ noise สูง Sensor หลัง firewall เห็นสิ่งที่ผ่าน preventive control แล้ว Sensor ระหว่าง critical zones เห็น lateral movement การใช้ Switched Port Analyzer (SPAN), network tap หรือ cloud traffic mirroring ต้องตรวจ packet loss, capacity, privacy และ legal scope

Encrypted traffic สร้าง trade-off ระหว่าง Confidentiality กับ visibility ทางเลือกคือ TLS termination/inspection ในจุดที่อนุมัติ, endpoint telemetry, flow metadata, DNS log และ application log หากถอดรหัสเพื่อ inspection ต้องจัดการ private key, certificate trust, sensitive data exposure, excluded categories, performance และ accountability อย่างชัดเจน

VPN สร้าง logical protected channel ผ่าน network ที่ไม่เชื่อถือ แต่ไม่ได้ทำให้ endpoint ที่ปลาย tunnel ปลอดภัย VPN มีสอง use case หลัก

  • Site-to-site VPN เชื่อม network หรือ gateway สองฝั่ง มักใช้ IPsec tunnel
  • Remote-access VPN เชื่อม user/device เข้าสู่ resource ขององค์กร อาจใช้ IPsec หรือ TLS-based solution

IPsec ทำงานที่ network layer และใช้ Authentication Header (AH) หรือ Encapsulating Security Payload (ESP) ตาม design AH ให้ integrity, data-origin authentication และ anti-replay กับส่วนที่ครอบคลุม แต่ไม่ให้ Confidentiality และเข้ากับ NAT ได้ยาก ESP สามารถให้ Confidentiality พร้อม integrity/authentication ตาม configuration และใช้แพร่หลายกว่า

Transport mode ปกป้อง payload ของ IP packet เดิมและมักใช้ host-to-host ส่วน tunnel mode ห่อ packet เดิมไว้ใน packet ใหม่และเหมาะกับ gateway-to-gateway หรือ remote-access หลายแบบ Internet Key Exchange (IKE) ใช้เจรจา Security Association (SA), authenticate peer และสร้าง key material Policy ต้องกำหนด peer identity, approved algorithm, lifetime, rekey, revocation และ logging ไม่ใช้ pre-shared secret เดียวร่วมกับผู้ใช้จำนวนมากหากมีทางเลือกที่จัดการ identity ได้ดีกว่า

TLS VPN ทำงานผ่าน TLS และอาจให้ access ระดับ application หรือสร้าง tunnel กว้างตาม product/design ข้อสอบมักให้เลือกตาม requirement: ถ้าต้องปกป้องทุก IP traffic ระหว่าง gateways ให้คิดถึง IPsec tunnel; ถ้าต้องให้ผู้ใช้นอกองค์กรเข้าถึง web application เฉพาะรายการ application proxy หรือ ZTNA อาจลด exposure กว่า full network VPN

Split tunneling ส่งเฉพาะ corporate traffic ผ่าน VPN ขณะที่ Internet traffic ออก local network ช่วยลด latency และ concentrator load แต่ device อาจเชื่อม trusted กับ untrusted network พร้อมกัน เพิ่ม path สำหรับ bypass monitoring หรือ pivot Full tunneling ส่ง traffic ทั้งหมดผ่าน organization control เพิ่ม visibility แต่ต้องมี capacity, privacy และ resiliency รองรับ คำตอบขึ้นกับ risk ไม่ใช่มีแบบหนึ่งถูกเสมอ

Remote access ที่ดีใช้ MFA, managed device posture, least privilege, per-application access เมื่อเหมาะสม, session timeout, logging และ rapid revocation Administrator และ third party ควรผ่าน bastion/jump host หรือ Privileged Access Management (PAM) path ที่จำกัด ไม่เปิด management interface สู่ Internet โดยตรง

ภาพนี้สรุปเส้นทาง remote access หลังตรวจ identity และ device posture โดยแยก application access, protected tunnel และ privileged administration ตาม requirement:

flowchart LR remote["Remote user or third party / device"] --> verify["MFA + managed device posture"] verify --> path{"Access path ตาม requirement"} path -->|"Per-application access"| appgw["Application proxy / ZTNA"] appgw --> app["Approved application"] path -->|"Protected tunnel"| vpn["Remote-access VPN"] vpn --> resource["Authorized resource"] path -->|"Privileged administration"| pam["PAM / bastion / jump host"] pam --> mgmt["Management interface"]

Wireless ใช้ shared radio medium จึงไม่มีรั้วกายภาพตรงกับ signal boundary ผู้โจมตีอาจอยู่นอกอาคาร การสำรวจ coverage, access point placement, transmit power และ rogue device จึงเป็นส่วนหนึ่งของ design ไม่ใช่เพียง performance tuning

มาตรฐานสำคัญ ได้แก่

  • WPA2 ใช้ AES-based CCMP ใน configuration ที่ปลอดภัย; legacy TKIP ไม่เหมาะกับ design ใหม่
  • WPA3-Personal ใช้ Simultaneous Authentication of Equals (SAE) แทน shared PSK exchange แบบเก่าและเพิ่มการต้าน offline password guessing เมื่อใช้อย่างถูกต้อง
  • WPA2/WPA3-Enterprise ใช้ IEEE 802.1X และ Extensible Authentication Protocol (EAP) กับ authentication server เช่น RADIUS ช่วยให้ identity ต่อผู้ใช้หรือ device และ revocation ดีกว่า shared password
  • Protected Management Frames (PMF) ปกป้อง management frame บางชนิดจาก spoofing/tampering แต่ไม่หยุด jamming

Enterprise EAP method มี trust model ต่างกัน หากใช้ certificate ต้อง validate server certificate และชื่อที่คาดหวัง ไม่เช่นนั้น evil twin อาจหลอกเก็บ credential Pre-Shared Key (PSK) เดียวทั้งองค์กรกระจายและเพิกถอนยาก; การเปลี่ยนพนักงานหนึ่งคนอาจต้องเปลี่ยนทุก device

Threat ที่พบบ่อย ได้แก่ rogue access point ที่ติดตั้งโดยไม่ได้รับอนุญาต, evil twin ที่เลียนแบบชื่อเครือข่าย, deauthentication/disassociation abuse, weak passphrase, Wireless Protected Setup (WPS) ที่เปิดโดยไม่จำเป็น, jamming และ client ที่เชื่อม SSID อัตโนมัติ SSID ที่ซ่อนไม่ใช่ security control ที่แข็งแรง และ MAC filtering ถูก spoof ได้

Guest wireless ควรแยกจาก internal network ใช้ client isolation เมื่อเหมาะสม จำกัด egress และมี acceptable-use/privacy handling Captive portal แสดงหน้า login หรือเงื่อนไขการใช้ แต่ไม่ให้ link encryption โดยตัวมันเอง ต้องดู WPA/OWE/VPN/TLS ตาม use case

ตัวอย่าง enterprise design: ใช้ WPA3-Enterprise หรือ approved enterprise mode, 802.1X, certificate-based EAP, managed device certificate, separate employee/guest/IoT segments, NAC, wireless IDS/IPS, centralized logging และ lifecycle สำหรับ access point/controller เมื่อมี legacy IoT ที่รองรับเพียง PSK ให้แยก zone และจำกัด flow แทนการลด security ของเครือข่ายหลักทั้งหมด

Software-Defined Networking (SDN) แยก control plane ออกจาก data plane เชิงตรรกะ ทำให้ controller กำหนด forwarding และ policy ผ่าน software ได้แบบรวมศูนย์ องค์ประกอบทั่วไปมี application layer, controller/control layer และ infrastructure/data plane

  • Northbound API เชื่อม application หรือ orchestration กับ controller
  • Southbound interface/API เชื่อม controller กับ network devices หรือ virtual switches
  • East-west interface อาจใช้ระหว่าง controllers หรือ domains ขึ้นกับ architecture

ข้อดีคือ automation, policy consistency, rapid provisioning, centralized visibility และ microsegmentation แต่ controller และ API กลายเป็น high-value target Risk รวม controller compromise, malicious application, weak API authentication, policy error ที่กระจายเร็ว, stale state, denial of service และ loss of controller connectivity

Controls ควรมี strong administrative identity, role separation, signed/approved application, API authentication/authorization, encrypted management channel, controller high availability, configuration versioning, change review, rate limit, telemetry และ tested fallback Data plane ต้องกำหนดว่าจะทำอย่างไรเมื่อ controller ติดต่อไม่ได้ เช่น fail static, preserve last known state หรือ deny new flow ตาม availability และ safety requirement

Network Functions Virtualization (NFV) นำ network function เช่น firewall, router หรือ load balancer มาทำงานเป็น software บน virtualized infrastructure SDN กับ NFV ใช้ร่วมกันได้แต่ไม่ใช่สิ่งเดียวกัน NFV เพิ่ม dependency ต่อ hypervisor, image, orchestrator และ resource isolation จึงต้องจัดการ supply chain, patching, tenant isolation และ performance exhaustion

Automation ลด manual inconsistency แต่ทำให้ mistake scale ได้เร็ว Infrastructure as Code (IaC) และ policy as code จึงต้องมี version control, peer review, automated validation, least-privileged deployment identity, drift detection และ rollback ที่ทดสอบแล้ว

Cloud networking ใช้ logical constructs เช่น Virtual Private Cloud (VPC) หรือ Virtual Network (VNet), subnet, route table, virtual gateway, load balancer, security group, network ACL, private endpoint และ cloud firewall ชื่อและ semantics ต่างตาม provider จึงต้องอ่าน behavior จริง ไม่สมมติว่า control ชื่อคล้ายกันทำงานเหมือนกัน

ประเด็นสำคัญมีดังนี้

  1. Shared responsibility: provider ป้องกัน physical network และ service layer ตาม model ส่วน customer มักรับผิดชอบ identity, route, firewall rule, exposed service, data และ workload configuration ระดับแบ่งหน้าที่เปลี่ยนตาม IaaS, PaaS, SaaS และ contract
  2. Logical isolation: tenant isolation ไม่ได้ทำให้ workload ภายใน tenant แยกกันโดยอัตโนมัติ ต้องกำหนด account/project/subscription, VPC/VNet, subnet, security group และ identity boundary
  3. East-west visibility: workload-to-workload traffic อาจไม่ผ่าน on-premises firewall ใช้ cloud-native flow log, workload firewall, service mesh, NDR หรือ microsegmentation ตาม architecture
  4. Management plane exposure: cloud API ควบคุม network ได้กว้าง ต้องใช้ MFA, workload identity, least privilege, organization guardrail, audit log และแยก deployment role
  5. Egress และ data exfiltration: private subnet อาจยังออก Internet ผ่าน NAT gateway หรือ service API ได้ ต้องกำหนด egress proxy/firewall, DNS policy, private endpoint และ allowlist ตาม requirement
  6. Resilience: availability zone และ region ลด failure บางประเภท แต่เพิ่ม routing, data consistency, cost และ failover complexity ต้องทดสอบ DNS, quota, key, identity และ dependency ไม่ใช่เพียงสร้าง subnet หลายแห่ง

Security group มักผูกกับ interface/workload และอาจเป็น stateful ขณะที่ network ACL มักผูกกับ subnet และอาจเป็น stateless แต่รายละเอียดขึ้นกับ provider จึงไม่ควรจำ generalization นี้เป็นสากล Route table กำหนดเส้นทาง ไม่ได้อนุญาต traffic แทน firewall และการไม่มี public IP ไม่ได้แปลว่าไม่มี outbound path หรือเข้าถึงจาก peered network ไม่ได้

การเชื่อม on-premises กับ cloud อาจใช้ Internet VPN, dedicated private circuit หรือ SD-WAN overlay Private circuit ให้ predictable connectivity และลดการผ่าน public Internet แต่ไม่ได้ให้ encryption โดยอัตโนมัติ ต้องกำหนด protection ตาม classification VPN บน private circuit อาจยังจำเป็นหาก threat model ต้องการ Confidentiality และ peer authentication

Peering เชื่อม virtual networks โดยตรง แต่ไม่ควรสมมติว่า routing transitive Transit hub/gateway ลด full mesh แต่เป็น critical dependency จึงต้องแบ่ง route domain, inspect traffic และป้องกัน route propagation ที่กว้างเกิน Hybrid DNS ต้องกำหนด authoritative zone, forwarding และ failure mode

Container และ Kubernetes เพิ่ม overlay network, ingress controller, service, pod identity และ NetworkPolicy หากไม่มี policy pod อาจสื่อสารกันกว้างกว่าที่ owner คาด ต้องบังคับ namespace/workload isolation, secure ingress/egress, service-to-service identity, secret/certificate lifecycle และ control ของ cluster management plane

Secure Access Service Edge (SASE) รวม wide-area networking กับ cloud-delivered security capabilities เพื่อรองรับ distributed users และ cloud applications แต่เพิ่ม dependency ต่อ provider, identity, policy synchronization และ telemetry ชื่อบริการไม่พิสูจน์ว่า Zero Trust หรือ least privilege ถูกนำไปใช้แล้ว

ตัวอย่าง cloud design: Internet request เข้า DDoS protection และ load balancer/WAF จากนั้นถึง application subnet ที่ไม่รับ inbound โดยตรง Application ติดต่อ managed database ผ่าน private endpoint และ workload identity; egress ผ่าน controlled gateway; administrator ใช้ privileged access path; ทุก rule สร้างจาก reviewed IaC และส่ง flow, DNS, WAF, identity กับ control-plane logs ไปยัง monitoring กลาง Design นี้ยังต้องทดสอบ authorization ใน application เพราะ network control ไม่แทน application security

NIST Cybersecurity Framework (CSF) 2.0 ใช้จัดการ network risk ในระดับ outcome ได้ตลอด Govern, Identify, Protect, Detect, Respond และ Recover ตัวอย่างเช่น Govern กำหนด owner และ supplier requirement, Identify ทำ asset/data-flow inventory, Protect ใช้ segmentation และ secure protocol, Detect ใช้ telemetry, Respond จำกัดหรือ isolate flow และ Recover ทดสอบ route/service restoration

เอกสาร NIST ที่เกี่ยวข้องโดยตรงและใช้เป็นแนวทาง ไม่ใช่ checklist ที่ใช้แทน risk assessment ได้แก่

  • NIST SP 800-41 Rev. 1, Guidelines on Firewalls and Firewall Policy อธิบายประเภท firewall, policy, deployment และ management
  • NIST SP 800-77 Rev. 1, Guide to IPsec VPNs ครอบคลุม IPsec และการวางแผน VPN
  • NIST SP 800-94, Guide to Intrusion Detection and Prevention Systems ครอบคลุม IDPS หลายประเภทและ lifecycle การใช้งาน
  • NIST SP 800-153, Guidelines for Securing Wireless Local Area Networks ครอบคลุม WLAN security ตลอด lifecycle
  • NIST SP 800-207, Zero Trust Architecture อธิบายหลักและองค์ประกอบของ ZTA โดยไม่ผูก trust กับ network location เพียงอย่างเดียว

เอกสารแต่ละฉบับมีขอบเขตและอายุ ต้องตรวจ version, organizational requirement และ technology context ก่อนใช้กับ production

ISO/IEC 27001:2022 กำหนด requirement ของ Information Security Management System (ISMS) ส่วน Annex A เป็นชุด reference controls ที่องค์กรเลือกตาม risk และบันทึกเหตุผลใน Statement of Applicability (SoA) ไม่จำเป็นต้องใช้ทุก control แบบเดียวกัน

หัวข้อที่สัมพันธ์กับ Domain 4 ได้แก่ security of networks, security of network services, segregation of networks, information transfer, logging, monitoring activities, configuration management และ supplier/cloud service controls ISO/IEC 27002:2022 ให้ guidance เพิ่มเติมในการนำ controls ไปใช้ จุดสำคัญคือกำหนด security requirement ใน service agreement, ระบุ responsibility, review configuration และเก็บ evidence ไม่ใช่เพียงซื้อ firewall แล้วถือว่าสอดคล้อง

COBIT 2019 เชื่อม network security เข้ากับ governance และ management objectives เช่น APO13 Managed Security, DSS05 Managed Security Services, DSS01 Managed Operations, BAI04 Managed Availability and Capacity และ MEA สำหรับ monitoring/evaluation ผู้บริหารใช้ COBIT กำหนด decision rights, responsibility, metric และ assurance มากกว่ากำหนด firewall syntax

ตัวอย่างการใช้ร่วมกัน: governance body กำหนด risk appetite, management ระบุ network service requirement และ control owner, operations ดูแล rule/configuration, security monitoring ตรวจ event และ independent assurance ประเมินว่า process กับ control ให้ผลตาม objective หรือไม่

ITIL 4 มอง network เป็นส่วนหนึ่งของ service value system Practices ที่เกี่ยวข้อง ได้แก่ information security management, infrastructure and platform management, monitoring and event management, incident management, change enablement, availability management, capacity and performance management และ service continuity management

ตัวอย่าง: การเปลี่ยน routing หรือ firewall rule ต้องมี risk-based change process, test, approval, communication และ rollback Emergency change อาจเร่งขั้นตอนแต่ไม่ควรละทิ้ง authorization กับ evidence ส่วน network alert ต้องเชื่อม event ไป incident ตาม impact ไม่สร้าง ticket ทุก packet จนทีมตอบสนองไม่ไหว

กรอบเหล่านี้ทำหน้าที่ต่างกัน ISO/IEC 27001 ให้ระบบบริหารและ auditable requirements, NIST ให้ outcome และ technical guidance, COBIT เชื่อม governance กับ management objectives และ ITIL จัดการ network ในฐานะบริการ ไม่มีกรอบใดแทน architecture หรือ risk decision เฉพาะองค์กรได้

ลำดับที่ใช้ได้จริงคือ owner กำหนด classification, criticality และ risk tolerance; architect สร้าง data flow, segmentation และ secure channel; engineer นำ control ไปใช้; operations monitor และเปลี่ยนแปลงอย่างควบคุม; assessor ตรวจ evidence; Risk owner ตัดสิน residual risk

คำศัพท์นิยาม
OSI modelแบบจำลองการสื่อสารเจ็ดชั้น ใช้จัดหน้าที่ protocol และวิเคราะห์ control/failure
TCP/IP modelแบบจำลอง protocol suite ของ Internet ที่มักแบ่ง Application, Transport, Internet และ Link/Network access
Encapsulationการห่อข้อมูลจากชั้นบนด้วย header/trailer ของชั้นล่าง
Data flowเส้นทางและเงื่อนไขที่ data เคลื่อนระหว่าง source, destination และ intermediary
Segmentationการแบ่ง network เป็นส่วนและควบคุมการสื่อสารระหว่างส่วน
Microsegmentationการบังคับ policy ละเอียดระดับ workload, application หรือ identity
DMZzone คั่นกลางสำหรับ service ที่ติดต่อระหว่าง network ต่าง trust level
Data planeส่วนที่ forward traffic ตาม decision ที่มีอยู่
Control planeส่วนที่เรียนรู้ topology และสร้าง routing/forwarding decision
Management planeinterface และ service สำหรับ configure, monitor และ administer network
Stateful firewallfirewall ที่ติดตาม state ของ connection เพื่อประกอบการตัดสินใจ
Proxyintermediary ที่รับ connection ฝั่งหนึ่งและติดต่ออีกฝั่งในนาม client/server
WAFfirewall ที่ตรวจและบังคับ policy กับ HTTP/application traffic
IDSระบบตรวจ event/traffic ที่น่าสงสัยและสร้าง alert
IPSระบบตรวจและสามารถ block หรือเปลี่ยน traffic ที่ตรงเงื่อนไข
VPNlogical protected channel ผ่าน network ที่ไม่เชื่อถือ
IPsecชุด protocol ที่ปกป้อง IP communication ด้วย AH/ESP และ Security Associations
TLSprotocol สำหรับปกป้อง application communication ด้วย authentication, key establishment และ record protection ตาม configuration
Split tunnelingการส่งเฉพาะ traffic บางส่วนผ่าน VPN และให้อีกส่วนออก local path
NACcontrol ที่ตัดสินหรือจำกัด network access จาก identity, device หรือ posture ตาม policy
802.1Xport-based network access control framework ที่ใช้ EAP กับ wired/wireless access
Evil twinaccess point ปลอมที่เลียนแบบเครือข่ายเพื่อหลอก client
SDNarchitecture ที่แยก control plane จาก data plane เชิงตรรกะและควบคุมผ่าน software
NFVการทำ network function เป็น software บน virtualized infrastructure
ZTAarchitecture ที่ไม่ให้ implicit trust จาก location และประเมิน access request ตาม policy/context
SASEarchitecture/service model ที่รวม WAN capabilities กับ cloud-delivered security functions
VPC/VNetlogical cloud network boundary ที่ customer กำหนด address, subnet, route และ controls
Private endpointinterface/address ส่วนตัวสำหรับเข้าถึง service โดยไม่ต้อง expose ผ่าน public endpoint ตาม provider design
Flow logmetadata ของ network flow เช่น source, destination, port, action และเวลา ไม่ใช่ full packet capture
Air gapการแยก network โดยไม่มี direct connectivity ตาม design แต่ยังต้องควบคุมช่องทางอื่น
Blast radiusขอบเขตผลกระทบที่ incident หรือ failure แพร่ไปถึงได้
  1. OSI เป็น model ไม่ใช่ packet capture จริงทั้งหมด ใช้หาชั้นที่เกี่ยวข้อง แต่อย่าฝืนให้ protocol หนึ่งอยู่ชั้นเดียวในทุกบริบท
  2. NAT ไม่ใช่ firewall การแปล address ไม่แทน traffic policy
  3. VLAN ไม่พอถ้า inter-VLAN routing เปิดกว้าง Segmentation ต้องมี enforcement
  4. Port 443 ไม่พิสูจน์ว่า traffic ปลอดภัย ต้องดู protocol, certificate, identity และ behavior
  5. Encryption ไม่เท่ากับ authentication Channel ที่ไม่ validate peer ยังเสี่ยง MITM
  6. DNSSEC ไม่ได้เข้ารหัส DNS query DoT/DoH จึงแก้คนละปัญหา
  7. Firewall กับ WAF แก้คนละระดับ WAF ไม่แทน application authorization และ secure coding
  8. IDS แจ้งเตือน; IPS หยุดได้ แต่ inline IPS มี Availability risk
  9. IPsec AH ไม่ให้ Confidentiality ESP ใช้ให้ encryption ตาม configuration
  10. VPN ปกป้อง channel ไม่ได้ทำให้ endpoint trusted ยังต้องมี MFA, posture และ least privilege
  11. Split tunnel มี trade-off ลด load แต่เพิ่ม path ที่อาจ bypass monitoring
  12. SSID hiding และ MAC filtering เป็น weak controls ไม่แทน WPA2/WPA3 และ 802.1X
  13. Captive portal ไม่ให้ link encryption โดยตัวมันเอง เป็น access/terms mechanism
  14. Zero Trust ไม่ได้ลบ network controls ใช้ identity/context ร่วมกับ segmentation
  15. Private cloud circuit ไม่ได้แปลว่า encrypted Private path กับ Confidentiality เป็นคนละ property
  16. ไม่มี public IP ไม่ได้แปลว่า isolated Peering, VPN, gateway และ API ยังสร้าง reachability ได้
  17. Redundant ไม่เท่ากับ resilient หากมี common failure ตรวจ path, power, DNS และ identity dependency
  18. ถ้าโจทย์ถาม FIRST ให้เริ่มจาก requirement/data flow อย่าเลือกผลิตภัณฑ์ก่อนรู้ allowed flow
  19. ถ้าโจทย์ถาม BEST ให้มอง lifecycle Control ต้อง monitor, review, test และ recover ได้
  • Domain 1: Security and Risk Management — ใช้ governance, risk appetite, policy, supplier agreement, Business Impact Analysis (BIA), Recovery Time Objective (RTO), Recovery Point Objective (RPO) และ residual risk กำหนด network requirement และ resilience
  • Domain 2: Asset Security — Data classification และ data states บอกว่า flow ใดต้อง encrypt, segment, monitor, retain log หรือห้ามออกนอก jurisdiction; Data owner กำหนด handling requirement
  • Domain 3: Security Architecture and Engineering — Trust boundary, defense in depth, cryptography, Public Key Infrastructure (PKI), Zero Trust, SASE, cloud shared responsibility, OT/ICS/IoT และ fail securely เป็นฐานของ network design
  • Domain 5: Identity and Access Management — 802.1X, EAP, RADIUS, MFA, service identity, federated identity, NAC, PAM และ certificate-based authentication ต้องเชื่อมกับ identity lifecycle และ authorization
  • Domain 6: Security Assessment and Testing — ตรวจ firewall rule, segmentation, wireless coverage, VPN configuration, detection coverage, failover, penetration path และ evidence ว่า control ทำงานตาม requirement
  • Domain 7: Security Operations — ดูแล configuration, patching, log, NDR/IDS alert, incident containment, DDoS response, change, backup, recovery และ third-party remote access ในงานประจำ
  • Domain 8: Software Development Security — Secure API, TLS validation, service mesh, application authorization, Infrastructure as Code, container network policy, CI/CD identity และ WAF ต้องออกแบบร่วมกับ Software Development Life Cycle (SDLC)

Network security ที่มีคุณภาพจึงไม่จบที่ “ต่อถึง” หรือ “ping ผ่าน” แต่ต้องพิสูจน์ได้ว่าเฉพาะ flow ที่ได้รับอนุมัติเท่านั้นที่ผ่าน, peer ถูก authenticate, data in transit ได้รับ protection ตาม classification, anomaly ถูกตรวจพบ, failure ถูกจำกัด และ owner เข้าใจ residual risk ที่ยังเหลืออยู่