Please enable JavaScript.
Coggle requires JavaScript to display documents.
MBU Architecture and Governance (Policies (Firewalls (Administrator…
MBU Architecture and Governance
Vision & Values
Align with Company Priorities
Create best-in-class customer experiences by putting customers first in everything we do
Invest in our networks and technology to deliver leading performance and reliability
Deliver innovative solutions and compelling content that our customers will love
Drive profitable growth in all the markets we serve
Develop our people and a high performing culture
Be a strong, socially responsible leader in our communities across Canada
2018 Corporate Objectives
Improve our end-to-end customer experience
Deliver improved network performance & IT system stability
Deliver solutions that will grow our core businesses
Deliver company-wide results & objectives
Make Rogers one of the best places to work in Canada
Develop a better local presence in our key regional markets
How We Work
Simplify and innovate
Take ownership of the what and the how
Equip people to succeed
Execute with discipline and pride
Talk straight, build trust, and over deliver
Partners/Vendors
Collaboration tools
Yammer
Sharepoint
OneDrive
Coggle
Master Control
Arista
Imagine
IP Transport
Providius
Evertz
Management Networks
Meraki
Arista
RADIO
Wide Orbit
Telos Alliance
Supply Chain
Ticketing
FIT
?
Google
Guiding Principles
Technical
Comply with corporate security and best practices
Corporate IT
CyberStarr
Asset Management
Access Control
Cryptography
Physical and Environmental Security
Operations Security
Communications Security
System Acquisition, Development and Maintenance
Supplier Management
Anti-Virus
REQUIREMENTS
In vendor database
Centralized
Automatically updated
Control CPU Prioritization
Access to all systems/subnets in COE
Support Linux, MAC, Windows server
VENDORS
Jump(?)
McAfee?
WHAT SYSTEMS REQUIRE
Versio Servers
User workstations
FTP Servers
Meet increasing requirements for UHD, 4K/8K, HDR.
Enable transition to all-IP
Align with industry standards (ex. SMPTE 2110)
"5-9's" Network Availability
Drive vendor interoperability
Organizational
Break down silos
Engage customers with increased content choices, and additional ways to consume that content.
Improve Revenue Streams
Pursue best of breed in all areas
Leverage collaborative tools
Reduce TTM (Time to Market)
Welcome new ideas
Operational
Drive down operational costs
Reduce manual workflows and human intervention.
Increase engagement and audience measurability (Quality of Experience)
Decrease operational complexities
Create new operational efficiencies
Eliminate pain points and workflow deficiencies
Decrease down time
Increase scalability, agility, and flexibility.
"Make the Network disappear"
Policies
IP Address Management IPAM
IP Schemas
Assigning new IP's
Database
Naming Conventions
Devices
Locations
Firewalls
Administrator Activities must be logged
Security events must be logged and monitored
Anti-spoofing
External signalling traffic must be validated and filtered (i.e. SIP)
Changes must be approved per change management
New rules configured to deny-by-default,
Internet or outside facing applications bust be hosted in designated DMZ's
Insecure network protocols, ports or applications must be filtered according to Network security standards
VLANs
VLAN Master List
VLAN Assignment
Inter VLAN Routing
Permissions
Shared permissions are not allowed
Active Directory
Groups
Users
Passwords
Masked when displayed
Must not be hard coded in scripts
New accounts or resets must be provided with a temporary password, changed at first login
Accounts not used for 90 days must be disabled, deleted after 150 days
Shared passwords are not allowed
Password reset links must expire after 24 hours
Default passwords must be changed
Complex passwords required for administrator and high privilege accounts
Administrators
Active Directory
MCR Admiinistrators
Meraki
RAMP Administrators
RAMP
Brent Innes
Adrian K
Drew K
Shorif J
MCR
Brian Learoyd
Souheil K
Ronald A
Frewall
Firewall Administrators
Change Management
Procedures
Documentation
Approvals
Multifactor Authentication
Cloud applications
VPN
External facing applications
Remote access
DHCP
DNS
Applications
Event Logging Enabled
Upgrades approved per change management policies
Remote Access
Logging enabled
Administrative activities must be logged
Single Port of Entry for Hosted Teamviewer
under consideration (Enterprise versions only)
Cisco webex
Bomgar
TeamViewer <<< Main choice
mobile app / accessibility required (TeamViewer only today)
we (Rogers) must control entry points for logging purposes
procedure for authenticating to be via Support Specialists
Architecture
Network engineering or Network architecture should be consulted to design and document appropriate network flows in Rogers Media
Projects should align with all business units
Production and non-production environments must be physically and/or logically segregated
Versions & Patches
Patches applied to any hardware or software based system must be approved per change management procedures unless
System, applications and network devices must have up to date security patches applied
Network devices must have approved (by Engineering/Technology) version of software or firmware installed
Antivirus
Applications
Remote Access
Teamviewer
Vendors
RAMP Administrators
MCR Administrators
VPN
RAMP Administrators
Asset Management
VimBiz
Existing?
Active Directory
Antivirus
Windows Defender
?
Content
Radio
Wide Orbit
Pathfinder
Master Control
RAMP
Magnum
VistaLink PRO