STMicroelectronics Testimony
NetSecOps: Aligning Networking and Security Teams to Ensure Digital Transformation
October 15, 2021 | Network & Cloud Automation
The network and security teams at STMicroelectronics (ST), an $10.2 billion semiconductor manufacturer (2020 revenue), use DDI management solutions from EfficientIP to improve their collaboration.
ST originally adopted EfficientIPโs SOLIDServer DDI (DNS, DHCP, and IP address management) solution to unify these core network services. The DIT organization chose EfficientIP after a series of requests for proposals and proof- of-concept implementations.
Aldo De Luca, network security manager for STโs manufacturing networks told EMA that his company needed a DHCP service that could manage hun- dreds of thousands of IP addresses across its manufacturing networks and its globally distributed enterprise network. โ[EfficientIP] was the most scalable for DDI,โ he said.
Key Benefits
Cost Effectiveness
Ease of Use
Smooth Implementation
Streamlining Zone-Based Firewall Rule Creation
ST launched a global initiative to reduce security risk by eliminating manual rules management in the zone-based firewalls that control traffic between the various subnets in the companyโs network.
โWe are working with EfficientIP to integrate their DDI solution with our [firewall] environment,โ De Luca said. โWe want to have zone-based security with our firewalls, so we wanted to classify every subnet in our manufacturing network and establish rules for zone communication.โ
The integration will allow network administrators, who are the most familiar with the various subnets in the network and the types of devices that are con- nected to those subnets, to classify each new subnet within EfficientIPโs IPAM tool. These classifications will automatically push new rules to the companyโs firewalls, ensuring that the zone-based firewall rulesets are accurate and up to date. De Luca said this integration makes it easier to transfer the knowledge of the network team to the security team that is responsible for firewall rules management.
โWe plan to apply this integration to other things in the future. It will enable future microsegmentation projects, like network access control,โ he told EMA. โIt gives the teams a foundation for working together in the future, not just on security, but for network automation, too.โ
Expanding EfficientIP Investment with DNS Security
More recently, ST adopted EfficientIPโs DBS Guardian Security solution to help secure the companyโs migration to the cloud. DNS is a common vector for malicious attacks in general. When enterprises move services to the cloud, malicious actors can compromise those services via DNS spoofing, DDoS attacks, and other methods.
โWe are moving part of our IT to the cloud, and we needed some extra security threat prevention and data leak prevention,โ De Luca said.
EfficientIP has been an excellent vendor partner, he said. When ST first began working with EfficientIP, the DDI vendor was an agile, early-stage startup. Over the years, EfficientIP has matured, becoming more structured along presales, sales, customer support, and professional services.
โHowever, they have kept their initial startup agility while transforming. They have a very high level of quality processes, they listen to our requests, and con- tinuously improve,โ De Luca said.
Key Resources
Simplify & Secure Your Network
When our goal is to help companies face the challenges of modern infrastructures and digital transformation, actions speak louder than words.