One person. One device. Multiple security environments.
ICT security is the most pressing risk most small and medium organizations face, and most of the advice about it is either too vague to act on or too technical to read. This is one page. It shows the whole model on a single A3 sheet: four separate security environments, the people and the devices that reach them, the controls that decide who gets in, and — the part most people miss — how hard it should be to get information out.
I want this disseminated, so it's free. Download it, print it, pin it next to the IT desk, take it to your next board meeting. If you're a consultant, use it with your clients. Attribution to SRMBOK is appreciated; no permission needed.
What's on the page
Five rules that fit in a sentence each — not all information belongs in one environment; one person and one device can reach several; controls tighten as sensitivity rises; seeing information is not permission to move it; classification, clearance and dissemination are different questions. Then the four enclaves side by side, a reach matrix showing which device gets into which enclave, the four gates information passes through on the way out, and the three questions every organization eventually has to answer: how sensitive is it, how far is this person trusted, and who may I share it with. Australian terminology is the worked example (PSPF Release 2026, ASD ISM and Essential Eight, FIRST TLP 2.0), with the United States alongside as a broad analog. Black-and-white and color editions.
What might each enclave be built on?
These are examples to get you going, not endorsements, and the list is nowhere near complete. The point of the poster is that the configuration and authorization make the enclave, not the product — the same platform can sit in Enclave 1 or Enclave 2 depending on how it's set up. None of these products is "approved for classified information" by being named here.
Enclave 1 — General / Collaboration.
Everyday work and sharing with outsiders. A Synology or QNAP NAS in the office; Dropbox, Box, Google Drive or OneDrive; Proton Drive, Tresorit or Sync.com if you want end-to-end encryption; Nextcloud if you'd rather host it yourself; Slack, Teams, Zoom, Notion, Trello for the collaboration around it; Proton Mail, Google Workspace or Microsoft 365 for mail.
Enclave 2 — Controlled corporate.
Often the same products, properly configured: Microsoft 365 with Entra ID conditional access, Intune device compliance and Purview sensitivity labels and DLP; Google Workspace Enterprise with context-aware access and endpoint management; Box Enterprise with Box Shield; Dropbox Business, Egnyte, Tresorit Business or Proton for Business. Add an identity provider (Entra ID, Okta, JumpCloud), hardware MFA keys (YubiKey, Google Titan) or passkeys, device management (Intune, Jamf, Kandji, Mosyle), a password manager (1Password, Bitwarden, Keeper) and managed backup (Backblaze, Veeam, Datto).
Enclave 3 — Protected / High-security enclave.
Your own high-side environment, reached through a virtual desktop so files never land on the laptop: Citrix DaaS, Azure Virtual Desktop or Windows 365, Amazon WorkSpaces, Omnissa Horizon; hardened thin clients or locked-down endpoints (IGEL, Dell Wyse ThinOS, HP thin clients) and a dedicated admin workstation; hardware tokens or smart cards. In Australia the platform is usually an IRAP-assessed cloud region or provider — Microsoft Azure Australia Central, AWS Sydney or Canberra, Vault Cloud, AUCloud, Macquarie Government — often built to ASD's Blueprint for Secure Cloud. Information gets out through a gate, not a share link: a secure email gateway (Mimecast, Proofpoint), content disarm and reconstruction (OPSWAT MetaDefender, Votiro, Glasswall), a data diode where it's justified (Owl Cyber Defense, Waterfall, Fend), and privileged-access controls for the administrators (Microsoft PIM, CyberArk, BeyondTrust, Delinea).
Enclave 4 — Government / lead-client protected network.
You don't build this one; someone else runs it and sets the rules. It arrives as the owner's laptop and token, a client's Citrix portal, a prime contractor's project environment, an agency collaboration platform such as GovTEAMS, or a secure data room (Kiteworks, Objective Connect). Nothing you have in Enclaves 1 to 3 carries over.
Who it's for
Owners and CEOs who need to understand the shape of the problem in two minutes; ICT managers and MSPs who need a picture the board will accept; consultants, contractors and suppliers working towards government or defence work who need to see where their own environment stops and the client's begins.
What it isn't
A conceptual model, not an implementation specification, a compliance checklist or a statement of any government's policy. Naming a product here doesn't make it suitable for classified information; that depends on configuration, governance and formal authorisation. Check the current PSPF, ISM and your client's rules before you build anything.
Zip File Contains
SRMBOK Guide to Secure ICT Enclaves · A3 · Edition September 2026 · black-and-white & colour · PDF & png
Implementation Guide
If you're looking for detail on how to implement something like this: SRMBOK guide to DISP
top of page
$0.00Price
Sales Tax Included
Books and Templates
If you're unable to locate a particular template or subject of interest on our platform, please do not hesitate to reach out to us. There's a high chance we have it in our extensive collection, ready to be shared with you. We're committed to assisting you in finding exactly what you need.
Best sellers
bottom of page
















