Network Infrastructure Document
Identifies substantive internal network-infrastructure design and topology documents. Topic phrases are retained for discovery; enforcement requires segmentation, trust-boundary, routing, VLAN, DMZ, data-flow, or firewall-design content, and high confidence also requires a populated address, VLAN, port, device, or rule detail.
- Type
- regex
- Engine
- boost_regex
- Confidence
- medium
- Confidence justification
- Medium confidence requires internal network-design content rather than a document title alone. High confidence adds deployable addressing, VLAN, port, device, or rule detail.
- Jurisdictions
- global
- Regulations
- SOCI Act 2018 (Cth), TIA Act 1979 (Cth)
- Frameworks
- CIS Controls, DISP, ISO 27001, NIST CSF, SOC 2
- Data categories
- technology, security
- Scope
- narrow
- Risk rating
- 8
- Platform compatibility
- Purview: Compatible, GCP DLP: Compatible, Macie: Compatible, Zscaler: Compatible, Palo Alto: Degraded, Netskope: Unsupported
Pattern
(?is)\b(?:network\s+(?:architecture|topology|diagram|design)\s+(?:document|specification)?|infrastructure\s+(?:design|architecture|documentation)|(?:logical|physical)\s+network\s+(?:diagram|design))\b
Should match
Network architecture document— Low-tier probe - document topic without internal design contentNetwork topology document showing VLAN segmentation, DMZ trust boundary, data flow, and routing zones— Medium-tier probe - substantive network design without populated live valuesNetwork architecture document: network segment VLAN 120, firewall hostname fw-prd-02, source IP 10.4.0.0/16, destination IP 10.8.2.10, TCP port 443— High-tier probe - design content with populated VLAN, device, address, and port details
Should not match
Social network analysis— Non-match 1Network of contacts in the industry— Business relationship, not technical infrastructureThe vendor brochure presents a network architecture for its product family.— Product overview without internal segmentation or addressingTraining example: network architecture document with VLAN 120 and source IP 10.4.0.0/16— Explicit training content must not enforce
Known false positives
- Product brochures, reference architectures, and public design guidance discuss network diagrams and segmentation without exposing an organisation's internal environment. Mitigation: Keep topic-only matches discovery-only and require segmentation, routing, trust-boundary, data-flow, or firewall-design content for enforcement.
- Training labs can include realistic VLANs, addresses, ports, device names, and firewall rules. Mitigation: Reject explicit template, demo, tutorial, sample-data, and training-example framing from enforcing tiers.