North/south vs. east/west (or: Where the security budget goes vs. where the attacker *actually* moves) 0 ▲ Global Nerdy 1 hour ago · Tech · hide · 0 comments I was working on one of my “back of the envelope” diagrams for a post on microsegmentation and decided to draw the one pictured above as a warm-up exercise. It turned out well enough that I thought it was worth posting on its own. You might find it useful with clients when they look at you with puzzlement when you talk about “north-south” versus “east-west” in network security. You can also use the text below when explaining the concepts; feel free to “copy, paste, and adjust to taste”: North-south crosses the boundary of your environment. A browser hitting your web tier, an API call from outside, your service calling a third party. Up and down the diagram, in and out. East-west stays inside. Web tier to app tier, app tier to database, service to service, pod to pod. Sideways across the diagram, and it typically never touches your perimeter controls at all. The entire traditional security stack is pointed at north-south. Firewall, WAF, load balancer, the DMZ, the VPN concentrator,… No comments yet. Log in to reply on the Fediverse. Comments will appear here.