DNZ Consulting LLC · Effective August 27, 2026 · Next review August 27, 2027
This policy states how DNZ Consulting LLC separates its networks and how it watches for network threats.
1. Scope and ownership
This policy applies to every system, device, and person that DNZ Consulting LLC uses to do business. DNZ Consulting LLC is a small company. The Managing Member owns this policy. The Managing Member also acts as the Security Officer and the Data Protection Officer.
The Managing Member reviews this policy one time each year. The Managing Member also reviews it after any security incident.
2. Network segregation
We run separate networks for different trust levels.
Work devices sit on the primary network.
Guests use a guest network. The guest network cannot reach a work device.
Internet-of-things devices sit on their own network. They cannot reach a work device.
No production database accepts a direct connection from the open internet.
3. Perimeter controls
The router firewall stays on. It denies all inbound traffic by default.
The operating system firewall stays on for every endpoint.
We open an inbound port only for a stated business need. We record the reason.
We disable remote administration of the router from the internet.
We change the default administrator password on every network device.
We keep router and access point firmware current.
4. Remote access
Remote access to a server uses SSH with a public key. Password login is off.
Administrative interfaces are not published to the open internet.
We use a virtual private network to reach a private corporate network.
5. Monitoring
The platform firewall logs blocked connections.
Our hosting and database suppliers provide request logs and alerting. We review them.
We alert on a failed authentication burst and on an unexpected administrative change.
We review network and access logs every month, and immediately after an alert.
6. Wireless
Every wireless network uses WPA2 or WPA3.
We do not use WEP. We do not run an open network.
We disable WPS.
7. Review
The Managing Member reviews this policy one time each year.