Related Posts
Great lunch time specials around the city?
Additional Posts in Cyber Security Bowl
Anyone ever heard of or worked for Sygnia?
Anyone working in Pharma industry?
Any tips or tricks for CSX certification?
Views on carbon black as a product?
New to Fishbowl?
Download the Fishbowl app to
unlock all discussions on Fishbowl.
unlock all discussions on Fishbowl.



The DMZ is behind a firewall and gateway and the servers have their own VLAN.
You are trying to eliminate the insider threat risk, as someone/application inside the DMZ and accessing the unencrypted data.
Agreed. However, to know whether to encrypt in transit one has to understand the impact of the data being disclosed and rest of the controls built into the architecture.
Google man in the middle attack. Someone can alter the data during transit
Worth thinking about what your trying to protect and what your trying to prevent from happening.
Couple of things to think about:
What is encrypting the data rest protecting you from?
What is preventing you from setting up an encrypted comms between the servers?
How does someone from the outside world interact with either server?
What is the data? How sensitive is it? Are there specific regulations for this data?
Case is too vague
There is nothing stopping you, but it depends on what the data is, who has access and other controls.
In general you want to think about defence in depth and assume everything is compromised. You don’t have to spend the earth for solutions but based then on the data and systems being attacked (get into threat modelling).
As a rule of thumb encrypt everything in transit, at rest and on the infra side.
Disagree with the last statement