vStream Digital Media

Network Security Policy

Last updated: 03/02/25

Definitions

TermDefinition
Companymeans vStream Digital Media
ShineVRmeans the ShineVR product developed and operated by vStream Digital Media
GDPRmeans the General Data Protection Regulation
Responsible Personmeans Andrés Pitt, CTO
VPCVirtual Private Cloud - isolated network environment within Google Cloud Platform
FirewallNetwork security system that monitors and controls incoming and outgoing network traffic based on predetermined security rules
TLSTransport Layer Security - cryptographic protocol for secure communications over networks
DDoSDistributed Denial of Service - cyberattack attempting to disrupt normal traffic by overwhelming target with flood of internet traffic
IDS/IPSIntrusion Detection System / Intrusion Prevention System - security technologies that monitor network traffic for malicious activity
Network SegmentationPractice of dividing a network into multiple segments or subnets to improve security and performance
Private IPIP address used for internal network communication, not directly accessible from public internet

1. Policy Statement

vStream Digital Media operates a cloud-native infrastructure with all systems hosted on Google Cloud Platform. This Network Security Policy establishes requirements and controls to protect the confidentiality, integrity, and availability of data transmitted across networks used by the Company and ShineVR applications.

The Company leverages Google Cloud Platform's robust network security capabilities whilst implementing additional controls specific to our business requirements. All network communications are encrypted, monitored, and controlled through defence-in-depth security measures.

Critical Context: vStream operates a cloud-first model with no customer or production data hosted at Company premises. All network security for production systems is managed through Google Cloud Platform infrastructure in European data centres.

2. Purpose

The purpose of this policy is to:

3. Scope

This policy applies to:

4. Google Cloud Network Architecture

4.1 Virtual Private Cloud (VPC)

VPC Configuration:

Network Isolation:

4.2 Firewall Rules and Access Control

Firewall Configuration Principles:

Mandatory Firewall Controls:

Firewall Rule Management:

4.3 Private IP Addressing

Database Network Security:

Internal Service Communication:

4.4 Network Segmentation

Environment Segregation:

Benefits of Segmentation:

5. Cloud Load Balancing and DDoS Protection

5.1 Google Cloud Load Balancer

Load Balancer Configuration:

DDoS Protection:

5.2 Cloud Armor (Web Application Firewall)

Cloud Armor Implementation:

Security Rules:

6. Wireless Network Security

6.1 Company Office Wireless Network

Encryption Requirements:

Network Configuration:

Access Control:

Important Context:

6.2 Home Network Security (Remote Work)

Employee Responsibilities:

Company Recommendations:

7. Encryption in Transit

7.1 TLS Encryption Requirements

Mandatory TLS Configuration:

Certificate Management:

7.2 ShineVR Application Traffic

Application-Level Encryption:

API Security:

7.3 Google Cloud Internal Traffic

Automatic Encryption:

7.4 Email Communication Security

Google Workspace Email Security:

7.5 Remote Access Encryption

Secure Remote Access:

VPN (If Implemented):

8. Network Monitoring and Intrusion Detection

8.1 Google Cloud Security Command Centre

Continuous Monitoring:

8.2 Network-Based Intrusion Detection

Google Cloud IDS Capabilities:

Intrusion Prevention:

8.3 Network Traffic Logging

VPC Flow Logs:

Firewall Logs:

8.4 Alerting and Response

Automated Alerting:

Response Procedures:

9. Network Redundancy and Resilience

9.1 Multi-Region Architecture

Geographic Distribution:

Google Cloud SLAs:

9.2 High Availability Design

Redundancy Principles:

Network Resilience Testing:

10. Remote Access and VPN

10.1 Cloud-Native Remote Access

No Traditional VPN Required:

Remote Access Requirements:

10.2 VPN (If Future Implementation)

If VPN Implemented in Future:

11. Third-Party Network Access

11.1 Third-Party Access Policy

General Prohibition:

Permitted Third-Party Network Access:

11.2 Third-Party Network Requirements

All third-party network access must:

Network Access Documentation:

See Vendor Management Policy for comprehensive third-party requirements.

12. Network Security for Development

12.1 Development Environment Network Security

Development Network Controls:

Development Network Requirements:

12.2 CI/CD Pipeline Network Security

Pipeline Network Architecture:

Pipeline Security Controls:

13. Compliance and Regulatory Requirements

13.1 GDPR Network Security

GDPR Article 32 - Security of Processing:

Data Residency:

13.2 ISO 27001 Alignment

Network Security Controls:

13.3 Healthcare Security Requirements

Customer Requirements:

14. Roles and Responsibilities

RoleResponsibilities
CTO (Responsible Person)Overall network security policy ownership; Google Cloud network configuration; firewall rule approval; Security Command Centre review; network security incident response; policy review and updates
Backend DevelopersImplement secure network configurations; configure Infrastructure-as-Code for network resources; assist with network security incident investigation; network security testing
Product ManagerNetwork security requirements for ShineVR features; customer network security requirement coordination
All EmployeesComply with wireless network security requirements; protect Company network credentials; report network security incidents; follow home network security guidelines (BYOD Policy)

15. Network Security Testing

15.1 Regular Security Testing

Automated Testing:

Manual Testing:

15.2 Vulnerability Management

Network Vulnerability Scanning:

Remediation:

16. Incident Response

16.1 Network Security Incidents

Types of Network Security Incidents:

Incident Classification:

See Incident Management Policy for comprehensive incident response procedures.

16.2 Network Isolation Procedures

Incident Containment:

Recovery:

17. Policy Review and Maintenance

Review Schedule:

Policy Updates:

18. Training and Awareness

18.1 Network Security Training

Required Training:

18.2 Developer Network Security Training

Technical Training:

19. Exceptions

19.1 Exception Process

Requesting Network Security Exceptions:

Approved Exception Documentation:

19.2 Emergency Exceptions

Emergency Network Changes:

20. Related Policies and Documents

This policy should be read in conjunction with:

21. Contact Information

Data Protection Officer / Chief Technology Officer:

Andrés Pitt
Email: andres@vstream.ie Phone: (086) 788 6570
Available 24/7 for P1 network security incidents

Company Address:

vStream Digital Media
37 Leeson Close
Dublin 2, D02 H344
Ireland

Website: vstream.ie