EnvSpec Naming Standard Introduces Strict Six-Environment Hierarchy for Zero Trust Infrastructure
The open standard EnvSpec Naming 1.0.0 argues that traditional host naming practices undermine security long before firewalls are configured. It claims that any environment labelled test, uat or pilot that processes real data is functionally prod and must be protected accordingly.
The specification defines a five-level hierarchy—environment, perimeter, system, slot, node—and mandates the canonical FQDN format {node}.{slot}.{system}.{perimeter}.{env}.{domain}. Names must be parseable by regular expressions and validating webhooks, allowing policies to be written against name suffixes rather than IP lists.
Only six environments are permitted: dev, test, stage, prod, infrastructure and workplace. Sandboxes, load-testing and pilot projects are treated as contours inside these environments, not new top-level categories. The decisive criterion is the nature of consumers and data, not hardware or project phase.
Key trust rules include: linear environments may not communicate directly; infrastructure alone may exchange artefacts and telemetry with all tiers; workplace devices reach any environment only via an access gateway; external parties are represented as external.{env} contours.
The standard explicitly forbids encoding mutable attributes such as site location, SLA or lifecycle status in names. It projects the same hierarchy into SPIFFE IDs, Kubernetes namespaces and three mandatory tags: envspec.io/env, envspec.io/perimeter and envspec.io/system.
Compliance can be verified automatically without maintaining a separate CMDB. Existing legacy hosts do not require renaming; applying the three tags at the hypervisor or cloud layer is accepted as full conformance.
Related articles
Security Vision Unveils Self-Assessment Portal for Unified Information Security Evaluation Across Corporate Holdings
Security Vision has launched a new Self-Assessment portal designed to consolidate information security self-evaluations for entire corporate groups and holdings. The platform addresses common challenges where subsidiaries maintain inconsistent compliance records, with some requirements fulfilled while others remain unresolved for years in scattered emails and spreadsheets. Security Vision SA covers the complete workflow from defining requirements and distributing questionnaires to calculating results and tracking remediation actions. Parent organizations gain a consolidated view of subsidiary compliance status along with detailed breakdowns by individual systems. The system supports requirement templates, version control, scheduled assessments, automated metric-based answers, and conversion of gaps into actionable plans with assigned owners and deadlines. Additional features include internal policy document management and interactive dashboards for analysis. The first public demonstration is scheduled for the SOC Forum on October 27-28.
Russian Websites Remain Dependent on Foreign SSL Certificates and Analytics Despite Sanctions
A Russian security researcher developed an open-source tool to scan websites for dependencies on foreign services that could be cut off abruptly. The scan of 50 major Russian sites including banks, retailers, telecoms, airlines, delivery services, online schools and government portals revealed that servers have largely been migrated domestically. However, critical components such as SSL certificates, analytics platforms and fonts remain tied to overseas providers. 43 out of 50 sites still use foreign SSL certificates, primarily from Belgian GlobalSign and American Let's Encrypt, while only four rely on the Russian NUC certificate from the Ministry of Digital Development. The study also highlights legal obligations under Roskomnadzor rules effective since March 2023 requiring prior notification for cross-border personal data transfers. Many sites continue using Google Analytics, Google Fonts and reCAPTCHA without realizing the compliance and resilience risks. The tool assigns letter grades from A to F based on the number of foreign dependencies detected.
Digitizing Cyber Risks: How to Communicate Cyber Threats to Boards in the Language of Money
The article from Solar details a hybrid methodology for quantifying cyber risks by converting technical threats into financial metrics such as probability and expected losses. It explains that cyber risks represent a specialized form of operational risk characterized by rapid propagation, scalability across IT infrastructure, and heavy dependence on third-party vendors and cloud providers. The process involves four stages: asset and threat identification, incident and vulnerability analysis, translation into monetary values using formulas like ALE, and ongoing monitoring with updates. Qualitative expert assessments are combined with quantitative techniques including Monte Carlo simulations and statistical modeling when data is available. The resulting metrics support investment prioritization through ROSI calculations, integration of cyber risks into enterprise risk management frameworks, and clear communication with directors and investors using business language. Regulatory pressure and the direct impact of incidents on revenue, costs, and business continuity make this approach increasingly essential.
Russian Interior Ministry Accuses Telegram of Ignoring Drug Trafficking Requests
The Russian Ministry of Internal Affairs has publicly stated that Telegram completely ignores requests from law enforcement agencies aimed at combating illegal drug trafficking. According to the ministry, the messenger has become one of the main platforms, alongside darknet markets, for involving teenagers in narcotics-related crimes. Acting head of the Main Directorate for Drug Trafficking Control Kirill Smurov highlighted that Telegram administration does not respond to official inquiries and refuses to share necessary information. In contrast, Yandex promptly removes prohibited content either independently or upon the first police request. Since 2022, approximately 153,000 crimes have been committed using Telegram, while Roskomnadzor has issued more than 150,000 content removal demands that received no response. Founder Pavel Durov, who is included in the Rosfinmonitoring list of terrorists and extremists, has not engaged with Russian authorities on these matters.