Healthcare providers, legal practices, and financial SMBs in California are subject to strict regulatory frameworks requiring cryptographic audit trails and microsegmentation of cardholder/ePHI data.
1. Required Network Compliance Controls
| Requirement | Standard Reference | Implementation Requirement |
|---|---|---|
| Encrypted Syslog Archiving | HIPAA § 164.312(b) / SOC 2 CC7.2 | TLS-encrypted forwarding to Loki/Graylog with 1-year immutable retention |
| Administrative Bastion MFA | PCI-DSS 8.3 / SOC 2 CC6.1 | Hardware FIDO2 WebAuthn or TOTP required for all SSH/web router logins |
| Microsegmentation | NIST SP 800-207 Zero Trust | Deny-all inter-VLAN firewall rules with explicit service port permits |