Critical Infrastructure Design

Identifies substantive critical-infrastructure and essential-service network or control-system designs. Topic phrases are retained for discovery; enforcement requires segmentation, data-flow, trust-boundary, VLAN, DMZ, firewall, or OT-zone design content, and high confidence also requires a populated address, VLAN, port, device, or rule detail.

Type
regex
Engine
boost_regex
Confidence
medium
Confidence justification
Medium confidence requires substantive design content in critical-infrastructure, essential-service, or OT scope. High confidence adds deployable network or device values.
Jurisdictions
au
Regulations
Criminal Code Act 1995 (Cth), SOCI Act 2018 (Cth)
Frameworks
CIS Controls, ISO 27001, NIST CSF
Data categories
infrastructure, security
Scope
narrow
Risk rating
10
Platform compatibility
Purview: Compatible, GCP DLP: Compatible, Macie: Compatible, Zscaler: Compatible, Palo Alto: Degraded, Netskope: Unsupported

Pattern

(?is)\b(?:critical\s+infrastructure\s+(?:network\s+)?(?:design|architecture|topology|diagram)|essential\s+service\s+(?:network|system)\s+(?:design|architecture|diagram)|(?:SCADA|ICS|OT)\s+(?:network|system)\s+(?:design|architecture|diagram))\b

Should match

Should not match

Known false positives