Architecture Considerations
Summary
PDF p.126When evaluating network architecture and selecting effective controls, consider factors such as cost, compute and responsiveness, scalability, availability, resilience, power, patch availability, and risk transference. These factors help ensure the architecture meets performance, security, and operational requirements.
In plain words
Supplementary — not from your PDFChoosing an architecture and its controls is a trade-off between cost, compute and responsiveness, scalability, availability, resilience, power, patch availability and risk transference. On-premises networks cost more upfront, are harder to scale, and are usually less resilient than cloud networking. Contracts and SLAs can transfer some risk to a third party.
Detailed explanation
PDF p.126-
Cost
- Up-Front Capital Outlay: Includes architecture changes, acquisition, and upgrades of appliances and software.
- Depreciation: Assets lose value over time.
- Maintenance and Support: Ongoing liabilities.
- Investment Value: Calculated based on reduced losses from incidents.
-
Compute and Responsiveness
- Minimize Processing Time: Ensure acceptable response time for workloads.
- Resources: Sufficient CPU, system memory, storage, and network bandwidth.
- Cost: Higher compute resources incur greater costs.
-
Scalability and Ease of Deployment
- Minimize Costs: When workloads increase or decrease.
- Capital Costs: Difficult to recover if workloads decrease.
- Deployment: Challenging to deploy new nodes or upgrade existing ones if workloads increase.
- Scalable System: Quickly or automatically adds/removes compute resources without excessive costs.
-
Availability
- Minimize Downtime: Maximize uptime.
- Impact: Downtime damages reputation, revenue, and profitability.
- Causes: Planned maintenance, unplanned failures, security incidents.
-
Resilience and Ease of Recovery
- Recovery Time: Reduce time to recover from failures.
- Manual Intervention: Systems that recover without manual intervention are more resilient.
-
Power
- Energy Demands: Facility must meet energy demands of devices and workloads.
- Cost: Higher compute resources increase power usage and costs.
- Infrastructure: Minimize power failures to improve availability.
-
Patch Availability
- Protection: Ensure firmware and software are protected against known vulnerabilities.
- Third-Party Management: Challenges when relying on third parties or unsupported devices/software.
-
Risk Transference
- Third-Party Management: Use contracts to manage network infrastructure.
- SLA: Define penalties for not meeting metrics for responsiveness, scalability, availability, and resilience.
-
On-Premises Networks
- High Capital Costs: Low scalability.
- Bandwidth Increase: Difficult to upgrade (e.g., from 1 Gbps to 10 Gbps).
- Recovery Procedures: Complex in large-scale disasters.
- Availability and Resilience: Lower compared to cloud networking.
Important terms
taken from the text above- Up-Front Capital Outlay
- Includes architecture changes, acquisition, and upgrades of appliances and software.
- Depreciation
- Assets lose value over time.
- Maintenance and Support
- Ongoing liabilities.
- Investment Value
- Calculated based on reduced losses from incidents.
- Minimize Processing Time
- Ensure acceptable response time for workloads.
- Resources
- Sufficient CPU, system memory, storage, and network bandwidth.
- Minimize Costs
- When workloads increase or decrease.
- Capital Costs
- Difficult to recover if workloads decrease.
- Deployment
- Challenging to deploy new nodes or upgrade existing ones if workloads increase.
- Scalable System
- Quickly or automatically adds/removes compute resources without excessive costs.
- Minimize Downtime
- Maximize uptime.
- Causes
- Planned maintenance, unplanned failures, security incidents.
- Recovery Time
- Reduce time to recover from failures.
- Manual Intervention
- Systems that recover without manual intervention are more resilient.
- Energy Demands
- Facility must meet energy demands of devices and workloads.
- Infrastructure
- Minimize power failures to improve availability.
- Third-Party Management
- Challenges when relying on third parties or unsupported devices/software.
- SLA
- Define penalties for not meeting metrics for responsiveness, scalability, availability, and resilience.
- High Capital Costs
- Low scalability.
- Bandwidth Increase
- Difficult to upgrade (e.g., from 1 Gbps to 10 Gbps).
- Recovery Procedures
- Complex in large-scale disasters.
- Availability and Resilience
- Lower compared to cloud networking.
Examples & real-world scenarios
Supplementary — not from your PDF- An SLA with penalties if a provider misses 99.9% uptime.
- Buying enough CPU and bandwidth for peak workloads.
- Choosing devices that the vendor still patches.
Scenario
A company's firewall appliance is end-of-life and no longer gets patches. Even if it works fine, it now carries unpatched-vulnerability risk. Patch availability is part of the architecture decision.
Common mistakes
Supplementary — not from your PDF- Judging a design only on upfront cost and ignoring maintenance, power and depreciation.
- Thinking outsourcing removes risk. An SLA transfers some of it, but you are still accountable.
Practical skills
Supplementary — not from your PDF- Compare two designs using the architecture considerations list.
What I should remember
Key Points PDF p.126-
Cost
- Capital Outlay: Acquisition, upgrades, depreciation.
- Maintenance: Ongoing support.
-
Compute and Responsiveness
- Processing Time: CPU, memory, storage, bandwidth.
- Cost: Higher resources, higher costs.
-
Scalability and Deployment
- Cost Management: Workload changes.
- Scalable System: Add/remove resources efficiently.
-
Availability
- Downtime: Minimize, maximize uptime.
- Impact: Reputation, revenue.
-
Resilience and Recovery
- Recovery Time: Manual vs. automatic.
-
Power
- Energy Demands: Costs, infrastructure.
-
Patch Availability
- Protection: Against vulnerabilities.
- Third-Party Challenges: Unsupported devices/software.
-
Risk Transference
- Third-Party Management: Contracts, SLA.
-
On-Premises Networks
- Capital Costs: Scalability, bandwidth upgrades.
- Recovery: Disaster complexity.
- Availability and Resilience: Compared to cloud networking.