Lloyds MS11.6 Secure Configuration and Change Management - configuration baselines aligned with industry benchmarks (CIS Critical Security Controls v8 + CIS Benchmarks for Windows + Linux + cloud + container + DISA STIGs where applicable) + Infrastructure-as-Code (IaC) per HashiCorp Terraform + AWS CloudFormation + Azure ARM + Google Cloud Deployment Manager + golden images + configuration drift detection + change management process aligned with ITIL v4 / ISO 20000 + Lloyds Realistic Disaster Scenarios change impact assessment + segregation of development + test + production environments + production access controls + emergency change process + rollback procedures. MS11.15 Network Segmentation and Perimeter Defence - defense in depth + perimeter security (next-generation firewall + Web Application Firewall + Distributed Denial of Service mitigation + secure remote access via VPN with MFA + Secure Access Service Edge (SASE) + Secure Web Gateway (SWG) + Cloud Access Security Broker (CASB)) + internal network segmentation (microsegmentation + VLAN + zero-trust network access ZTNA) + east-west traffic inspection + Network Detection and Response (NDR) + DMZ architecture + cloud network security (VPC + security groups + Network Access Control Lists) + DNS security + DNSSEC + secure email gateway + insurance market connectivity via PRA-supervised IT infrastructure + Lloyds Marketplace Centralised Functions interconnection. Patch management integration. Cloud Security Posture Management (CSPM) for cloud configuration + Cloud Workload Protection Platform (CWPP) for workload security.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.