Multi-enclave identity & domain isolation for a naval System of Systems
- Context
- A naval management system is being designed as a System of Systems: discrete subsystems of differing sensitivity, spread across afloat and shore capability, that must keep working in denied, disrupted, intermittent and limited-bandwidth conditions.
- Decision
- Allocate user, infrastructure, management and security services per operating domain, with explicit boundary demarcation and controlled information transfer between enclaves. Identity is brokered between shore and afloat, privileged access is governed separately, and a standard service catalogue gives every enclave the same repeatable patterns.
- Outcome
- Low-level design traces in both directions from security control narratives to the configuration baseline. It supports assessment and authorization, and it is proven in a land-based test environment before shipboard installation.