header
 
image
 
 
I.  WEBSERVER TIER:

This includes DNS, SMTP, HTTP protocols and applicable HTTPS servers. Systems within this tier are among the most vulnerable to attack because they are exposed to the public internet. The security recommendations made are of specific importance to these systems.

II. APPLICATION SERVER TIER:

This Tier contains all systems that communicate with the Web server or Database Server Tiers. Although systems located on this Tier are not directly exposed to any external network, they have significant access permissions to the information stored in the backend database. Therefore, Systems within this Tier must also be secured.

III. DATABASE SERVER TIER:

This Tier contains the crown jewels of the environment. This normally includes Relational Database Servers (RDBMS), internal DNS Servers and others. The Server located within this Tier provides all services required by the Application Server and Database Server Tiers. Although direct access from outside the environment is not provided fro these systems, they too should be made secure.

IV.  STORAGE AREA NETWORK TIER:

This Tier is for wide deployment of IP Based Storage Area Network (SAN) Device. These devices or Systems usually provide storage to the subset of Servers located on Database server Tier, and therefore must be isolated from the rest of the network traffic by having its own network and dedicated connections to third party storage.

V. BACKUP TIER:


Backing up critical data is crucial for system support, however only those systems with changing data should be backed up. Each connection presents an intruder with an access mechanism into the contents of the backup Tier. Access to the backup Tier can provide the same information as the system being backed up.

VI. EXTRA NET / SERVICE PROVIDER TIER:


Information and Services from external sources are required is almost every e-commerce data center. The information may be as simple as stock information for a stock Server or it may be as complex as shipping inventory information. Servers need locating within the data center, or private leased lines may be used. In either case, the Extranet Tier is the location in which all connections (Used by either of the Database Server Tier or Application Server Tier) must be located. If the information is to be used by other Tiers within the Architecture, then a separate Extra Net Tier should be created to contain the necessary hardware.

VII. MANAGEMENT TIER:

The Management Tier is considered by some to be the most important and vulnerable tier within the Architecture. This Tier contains all networks and server manages software. Simple Network Management Protocol (SNMP) Servers are located within this Tier. Additionally, terminal concentrators provide console access to each of the servers located in this Tier.