Network Environment
Switching, routing, Wi-Fi, DNS, and network segmentation checks
Networks are where undocumented decisions accumulate. A VLAN added during an office move, a static route from a migration that finished two years ago, a guest network that was supposed to be temporary. Each one was sensible at the time and none of them were written down.
This library walks the environment methodically, so the configuration you think you have and the configuration you actually have stop being different things.
What this library checks
- VLAN inventory and whether segmentation matches the intent behind it
- Guest and IoT network isolation, including what those networks can still reach
- Switch configuration backups, firmware currency and end-of-support hardware
- Routing tables, static routes and the ones nobody can explain
- DNS configuration, internal resolvers, forwarders and filtering
- Wireless coverage, authentication method, PSK rotation and rogue AP detection
- Spanning tree, port security and unused port posture
Evidence you will be asked for
Every check in Spectra Core carries its own evidence. These are the artefacts an auditor, insurer or board most often wants to see for this area.
- Current network diagram with a date on it
- Configuration backup timestamps for each managed device
- Wireless authentication configuration and guest network isolation proof
Where this usually goes wrong
Segmentation is the control most often claimed and least often verified. Saying the guest network is isolated takes a sentence; demonstrating it takes a test, and the test is what an auditor asks for.
Run this library against your environment
Every check comes with a risk level, a review frequency, an assignee and a plain-language rationale, so the output reads for leadership as well as for engineers.
Other libraries
Remote Monitoring & Management
Alerting, patching, agent health, and endpoint visibility standards
Active Directory Configuration
GPOs, OU structure, password policies, and domain hygiene
Network Security
Identity, access management, and endpoint protection / EDR standards
Microsoft 365 Security
Identity threat detection and response, conditional access, and tenant hardening
Backup & Disaster Recovery
On-premise DR systems and Microsoft 365 backup configuration checks
Server Rooms
Physical environment, cooling, fire suppression, and monitoring standards