Network Monitoring Policy
Purpose
Section titled “Purpose”This policy defines how Cadence OneFive monitors network services for security, availability, and performance, in accordance with ISO 27001:2022 control A.8.21.
This policy applies to all network services used by Cadence OneFive, including cloud-hosted infrastructure, DNS, proxy and edge services, VPN, and SaaS platforms within the ISMS scope.
Network Services Inventory
Section titled “Network Services Inventory”| Service | Provider | Function | Security Mechanisms |
|---|---|---|---|
| Application hosting and databases | Fly.io | Production, staging, and development environments | Private networking, WireGuard VPN, TLS termination |
| DNS, proxy, and edge security | Cloudflare | DNS resolution, DDoS protection, web application firewall, Zero Trust | TLS 1.2+, WAF rules, bot management, Zero Trust access policies |
| File storage | AWS S3 | Knowledge base snapshots, file storage | Encryption at rest (AES-256), bucket policies, access logging |
| VPN | Cloudflare Zero Trust / WireGuard | Secure access to private infrastructure | WireGuard encryption, device posture checks |
| Secrets management | Doppler | Environment variable management across environments | Encryption at rest and in transit, audit logging, role-based access |
Monitoring Requirements
Section titled “Monitoring Requirements”Availability Monitoring
Section titled “Availability Monitoring”- Production application uptime is monitored continuously via Fly.io health checks and Sentry
- Uptime target: ≥ 99.5% monthly, excluding planned maintenance windows (per ISMS §6.2)
- Downtime and service degradation events are reported via Sentry alerts to the engineering team
Security Monitoring
Section titled “Security Monitoring”- Edge traffic: Cloudflare provides real-time visibility into traffic patterns, blocked threats, and bot activity
- Network access: Cloudflare Zero Trust logs device posture, user authentication, and access policy enforcement
- Infrastructure access: Fly.io logs SSH and WireGuard VPN connections to production machines
- DNS: Cloudflare monitors DNS query patterns and flags anomalies
Performance Monitoring
Section titled “Performance Monitoring”- Application response times and error rates are monitored via Sentry
- Database performance metrics are available through operation dashboards
- Cloudflare provides latency, cache hit ratio, and bandwidth metrics at the edge
Service Level Monitoring
Section titled “Service Level Monitoring”Network service providers are evaluated annually as part of the Vendor Management Policy, including:
- Review of provider SOC 2 reports
- Assessment of actual uptime against published SLAs
- Review of security incident disclosures from providers
- Evaluation of support responsiveness
Alerting
Section titled “Alerting”- Sentry alerts are routed to the engineering team via Discord for application errors and availability issues
- Fly.io health check failures trigger automated alerts
Alert thresholds and routing are reviewed quarterly to reduce noise and ensure critical events are surfaced.
Roles and Responsibilities
Section titled “Roles and Responsibilities”| Role | Responsibility |
|---|---|
| Head of Platform | Accountable for network service security and availability; approves changes to monitoring configuration |
| CISO | Reviews network security monitoring coverage; incorporates findings into risk assessments |
| Engineering Team | Configures and maintains monitoring and alerting; responds to alerts; investigates anomalies |
Related Documents
Section titled “Related Documents”- Log Management Policy — Application and security log collection, retention, and analysis
- VM Hardening Policy — Host-level firewall and network access controls
- Remote Access Policy — VPN and remote access requirements
- Vendor Management Policy — Network service provider evaluation
Policy Review
Section titled “Policy Review”- This policy will be reviewed annually and updated as necessary to reflect changes in network services, monitoring tools, or security requirements.
- Last reviewed/updated: 2026-08-25
Internal & Confidential: This page is only available in the internal handbook and contains confidential information.
