About This Architecture
Comprehensive bank enterprise security and network architecture spanning 50+ key controls across perimeter, core, and access layers on OCI infrastructure. Traffic flows from bank branches, mobile users, and internet through WAN boundary controls including SASE edge, ZTNA gateway, secure web gateway, and GSLB before reaching DMZ with NGFW, WAF, and API protection. Core layer implements micro-segmentation, SOAR, SIEM, and continuous exposure management, while identity layer enforces IAM, PAM, MFA, and HSM across VLAN 10, and data layer applies DLP, encryption, and immutable backups in VLAN 20. This architecture demonstrates defense-in-depth with threat detection (EDR, XDR, NDR, UEBA), deception controls (honeypots), and risk management (GRC, 3rd party risk, fraud detection). Fork and customize this diagram on Diagrams.so to align with your bank's compliance requirements, threat model, and OCI deployment topology. The modular design supports phased implementation across branches, mobile endpoints, and core banking systems while maintaining zero-trust principles and regulatory alignment.