For smaller organizations, your System Tree might be simple and contain only a few groups. For larger organizations, we recommend that you must plan systems and group them depending on the unique needs of your network and business. Grouping systems with similar properties or requirements enables you to manage policies for systems in one place, rather than setting policies for each system individually.
Consider the following criteria to classify the systems into groups:
Criteria to consider | Description |
|---|---|
Geographic location | Organize your System Tree in a manner which balances protection and performance. Organize your System Tree to make the best use of network bandwidth. Consider how the server connects to all parts of your network, especially remote locations that use slower WAN or VPN connections, instead of faster LAN connections. You might want to configure updating and agent-server communication policies differently for remote sites to minimize network traffic over slower connections. |
Network Location | Many large networks are divided by individuals or groups responsible for managing different parts of the network. Sometimes these borders do not coincide with topological or geographic borders. Who accesses and manages the segments of the System Tree affects how you structure it. |
Functional borders | Some networks are divided by the roles of those using the network; for example, Sales and Engineering. Even if the network is not divided by functional borders, you might need to organize segments of the System Tree by functionality if different groups require different policies. |
Business Unit | A business group might run specific software that requires special security policies. |
Sub-business unit | Supplementary business units that isn't a separate business unit but require the dedicated security policies and management. |
Function | The Servers group that has different server types based on function or role. For example, AD Domain controllers, Mail servers, Sharepoint servers, and SQL servers. |
Endpoint type | Classify the devices in your network and group them into laptops, servers, and desktops. |
Operating Systems and software | Consider grouping systems with similar operating systems to manage products and policies more easily. If you have legacy systems, you can create a group for them and deploy and manage security products on these systems separately. Alternatively, you can assign a tag to systems based on the operating system type. |
After you decide on the basic building blocks for groups in the System Tree, you must determine which building blocks to use and in which order based on these factors:
Policy assignment — Do you have many custom product policies to assign to groups based on chassis or function? Do certain business units require their own custom product policy?
Network topology — Do you have sensitive WANs in your organization that a content update might easily saturate? If you have only major locations, this is not a concern for your environment.
Client task assignment — When you create a client task, such as an on-demand scan, do you need to do it at a group level, like a business unit, or system type, like a web server?
Content distribution — Do you have an agent policy that specifies that certain groups must get their content from a specific repository?
Operational controls — Do you need specific rights delegated to your ePO - On-prem administrators that allow them to administer specific locations in the tree?
Queries — Do you need many options when filtering your queries to return results from a specific group in the System Tree?
After you choose the system groups for your tree structure, test the design for maintenance, performance, and protection with a few sample System tree models. There is no specific way to grouping systems, however the design you choose impacts the maintenance work in future.
Here are a few System Tree designs:
Example -1
Network location | Endpoint type | Operating system platform |
|---|---|---|
Los Angeles | Desktop | |
Laptop | ||
Server | Windows | |
SQL | ||
Linux | ||
San Francisco | Desktop | |
Laptop | ||
Server | Windows | |
SQL | ||
Linux |
Example -2
Business Unit | Geographic location | Endpoint type | Operating system platform |
|---|---|---|---|
Accounting | Los Angeles | Server | Windows |
Mumbai | Server | Macintosh | |
Windows | |||
London | Server | Linux | |
Windows | |||
SQL | |||
Management | Los Angeles | Desktop | Windows |
Mumbai | Laptop | Macintosh | |
Windows | |||
London | Server | Linux | |
Windows | |||
SQL |