skip to content

Your segmentation diagram backs a customer contract, but an intruder would meet no filter on the real path - what do you do, and who signs for it?

level: principalimportance: nice to knowfreq 32%

answer

  1. three clocks: exposure, assertion, funding
  2. the disclosure decision is not the network team's
  3. compensating controls now, described honestly
  4. windows are authorised by application owners
  5. re-scoping the boundary is not remediation

basics

~20 s

Separate three problems: an unenforced boundary, an assertion already made to a third party, and a remediation nobody has funded. The technical gap gets compensating controls and a dated plan; the assertion is a legal and contractual question that is not the network team's to sit on; the outage windows belong to business owners who can refuse them.

solid answer

~50 s

First stop the clock on the claim: from the moment you know the boundary is not enforced, the statement in the contract is known-false, and deciding whether and when to tell the customer is a legal and commercial call, not a network one. Escalate it with evidence, not with an opinion. Second, buy what you can this week without a window - deny the specific pair as close to the endpoints as you can reach, add monitoring on the bypass path, and record what you have and have not covered. Third, cost the real fix and name the owners: the address-plan or fabric work, the maintenance nights, and the fact that each night's outage risk is authorised by the application's business owner, who is entitled to refuse. Bring that as a dated plan with milestones you can evidence. What you must not do is redraw the diagram, or quietly re-scope the attested boundary so the gap falls outside it - both convert a finding into a misrepresentation.

go deeper

for a junior

Know that a control described in a customer contract creates obligations beyond the network, and that discovering it is absent is something you escalate rather than fix silently.

for a middle

Be able to describe realistic interim mitigation and to state precisely what it does and does not cover, rather than claiming equivalence with the missing boundary.

for a senior

Show that you would build the remediation plan around named window owners, dated exceptions and a cleanup step, and that you report containment per zone pair rather than per milestone.

for a principal

Own the separation of the technical gap, the third-party assertion and the funding decision, put disclosure with legal and commercial, and refuse the two shortcuts - redrawing the diagram and re-scoping the attested boundary.

## Why this is a judgment question and not an engineering one Everything technical here is already decided: the traffic bypasses the boundary, enforcement has to move, and moving it takes a programme of change nights. What makes it a principal-level question is that three different clocks start at once and they belong to three different people. 1. **The exposure clock.** An intruder on either side has an unfiltered path today. 2. **The assertion clock.** Your organisation has told a customer - in a contract, a security questionnaire, an attestation, an architecture appendix - that this separation exists. You now know that statement is false. Continuing to make it, or to renew it, with knowledge is a materially different thing from having been wrong. 3. **The funding clock.** The fix consumes engineering time, maintenance windows and possibly re-addressing work, none of which has a budget line yet. Most failures here are a category error: treating (2) and (3) as consequences of (1) that the network team can manage privately. ## The assertion is not yours to sit on The instinct - fix it quietly, tell nobody, avoid alarm - is understandable and is the wrong call, for a reason that is not moralistic. Contracts commonly contain notification obligations triggered by known control failures, and questionnaires and attestations are renewed on a cycle. If the next renewal is signed while you personally know the control is not in place, the organisation has made a knowing misstatement, and the person who knew and did not escalate is the person the record will name. So the escalation is: evidence of the gap, scope of what it affects, what has been done immediately, and the plan with dates - handed to whoever owns customer commitments, with legal and compliance in the room. Let them decide disclosure. Your job is to make sure the decision is made by people with the authority to make it, and that the decision is recorded. The two disqualifying moves are worth naming because both get proposed in real rooms. Redrawing the diagram to match reality and closing the finding as "documentation corrected" removes no reachability at all. Re-scoping the attested boundary so the bypass falls outside the described environment turns an operational gap into a description that is now shaped to avoid the truth. Both should be argued down explicitly. ## Buy what is cheap now A dated plan is not a control. Between the finding and the cut-over there is usually something that needs no maintenance window and no business sign-off: denying the specific offending pair at whichever enforcement surface is already on that path, tightening what is reachable at the endpoints, or - at minimum - instrumenting the bypass path so that use of it is at least observed. State honestly what each of these does and does not cover, because a compensating control described as equivalent is how a real gap disappears from a risk register. ## Who can refuse, and what that means for the plan This is the part junior plans always miss. The network team does not own the outage. Each maintenance night carries risk to an application, and the person entitled to accept or refuse that risk is that application's business owner. A remediation plan that assumes forty windows will be granted because security asked is not a plan; it is a wish. The credible version names, per zone pair: the owner, the proposed window, the flows at risk, and the rollback. Where an owner refuses, that refusal is itself a decision that belongs on the risk register with a name against it - which is usually what finally releases the budget, because an accepted risk with an owner behaves very differently in a governance forum than an engineering complaint. Budget for the unglamorous parts too: the discovery effort, the flow-to-owner mapping, and the cleanup change that removes the bypass path. Programmes that stop before cleanup have bought a slide, not containment. ## What you report, and in what units Report containment in units an intruder would recognise: zone pairs whose traffic now transits an enforcing device with policy active, exceptions still live and their expiry dates, and the paths still unfiltered. Do not report project completion; a programme can be eighty per cent complete with the exact pair that matters untouched. ## The answer that lands in an interview Name the three clocks, put the disclosure decision with legal and commercial rather than with yourself, buy immediate partial mitigation without overstating it, and present a plan whose windows have named owners who are allowed to say no. Then say plainly what the interviewer is listening for: until enforcement is on the path, the contract describes a control the customer does not have.

  • An executive proposes updating the diagram and the appendix to describe the network as it is. Your response?
    Accurate documentation is right and should happen, but it is not remediation and must not close the finding. Reachability is unchanged, and if the appendix is what the customer was sold, redrawing it to describe a weaker separation is a change to the commitment, which is a commercial conversation with the customer rather than an internal edit. Keep the two things separate in the record: documentation corrected, control still absent, plan dated.
  • Two business owners refuse the maintenance windows outright. What now?
    Their refusal becomes a recorded risk acceptance with their names and a review date, escalated to whoever sits above both. That does two useful things: it puts the decision where the authority is, and it usually surfaces the budget for a lower-risk path - a parallel build, a redundant service so the cut can be done without downtime - because a named acceptance is far more uncomfortable in a governance forum than an engineering request was.
  • How do you decide what counts as an adequate compensating control in the meantime?
    By what it actually removes, stated in reachability terms: which source-destination pairs can no longer be reached, on what paths, and what remains open. Monitoring is not a compensating control for reachability - it changes detection, not what the intruder can touch - and describing it as equivalent is how the gap quietly leaves the register.

saying these in an interview costs you the question

  • Fixes it quietly and lets the next attestation be signed anyway
  • Re-scopes the attested boundary so the gap falls outside it
  • Calls the corrected diagram the remediation
  • Assumes maintenance windows will be granted because security asked
  • Presents monitoring as a compensating control for reachability
  • Reports project completion instead of zone pairs enforced

context