All books

Professional

Apps About Coach Log in Start reading

Quantitative Finance · Glossary

What is Network segmentation, zero-trust architecture?

Also known as: network segmentation · zero-trust architecture

Definition 29.7 Research, Data and Risk Platforms · Chapter 29 — Security

Network segmentation divides a firm’s network into zones — trading, research, corporate, the outside — with traffic between zones allowed only on stated paths, so that a compromise in one zone does not reach the others. A zero-trust architecture grants no implicit trust for being inside a network: every request is authenticated and authorised on its own, by identity and device, before a session to a resource is established.

The chapter’s network zones and the only paths allowed between them. The trading zone, which holds the venue keys, talks to venues and sends fills to research; parameters come back only through chapter 16’s reviewed path; nothing from the corporate zone or the internet reaches it directly.
Figure 29.2. The chapter’s network zones and the only paths allowed between them. The trading zone, which holds the venue keys, talks to venues and sends fills to research; parameters come back only through chapter 16’s reviewed path; nothing from the corporate zone or the internet reaches it directly.
Read in context →