How-To Guides/Network Scope Diagram
Network Scope · Diagram ~25 minutes

How to Build a Network Scope Diagram in AllowNow

A network scope diagram is the map auditors ask for first: it shows exactly which networks, systems, and data stores are in scope for a control (PCI DSS cardholder data, SOC 2 production, GDPR personal data) and how traffic flows between them. AllowNow gives you an interactive canvas to draw it, a Live flag so the current diagram is unambiguous, one-click PNG export, and an annual recertification workflow so it never goes stale.

Prerequisites

  • AllowNow owner access — Network Scope lives in the sidebar
  • A rough idea of your in-scope boundary (which VPCs/subnets carry regulated data)
  • Any plan works — every plan includes 1 diagram; Enterprise includes unlimited diagrams
1

Create a scope diagram

1 minute

Go to Network Scope in the sidebar and enter a name that describes the boundary — for example PCI Cardholder Data Environment or Production (SOC 2). Click Create to open the editor.

Plan limit: every plan includes one network scope diagram. If you manage multiple environments and need a separate diagram for each, upgrade to Enterprise for unlimited diagrams.
2

Add your in-scope infrastructure as typed nodes

10 minutes

Use the palette on the left to drop typed nodes onto the canvas. Each type is a distinct compliance object, so the diagram doubles as an inventory:

Network / SubnetA VPC, VLAN, or CIDR range — the boundary that defines what is in scope.
InstanceA server, VM, or container workload that stores, processes, or transmits in-scope data.
DatabaseA managed or self-hosted datastore holding regulated data (cardholder data, PII, ePHI).
Security GroupA firewall rule set controlling traffic to and from the resources it protects.
WAFA web application firewall filtering inbound HTTP(S) traffic before it reaches your apps.
Load BalancerThe ingress that distributes traffic across instances — often the scope entry point.
Gateway / ServiceAn API gateway, third-party service, or external system the environment depends on.

Click any node to edit its details — name, CIDR range, cloud provider and region, and whether it is in scope. Recording out-of-scope systems and connecting them to the boundary is just as valuable: it documents the segmentation that keeps them out of scope.

3

Connect nodes to show data flow

5 minutes

Every node has four connection points — top, right, bottom and left — so you can route edges cleanly without lines crossing. Drag from any point on one node to any point on another to draw a connection. Use edges to show the path regulated data takes: internet → WAF → load balancer → instance → database.

4

Add titles and label zones with text

2 minutes

Add a Text / Title element from the palette to caption zones (“DMZ”, “Private subnet”, “PCI CDE”) or to add a title block. Text elements have no connection points — they are purely for annotation and make the exported diagram readable to an auditor who has never seen your infrastructure.

5

Mark the diagram Live and save

1 minute

Toggle Live on when this diagram represents your current, authoritative environment. Then click Save — all nodes, edges and layout are persisted together.

Why Live matters: only Live diagrams enter the annual recertification workflow and appear in compliance reports. Keep working drafts un-flagged so they don't generate review reminders.
6

Export a PNG and include it in reports

1 minute

Click Export PNG to download a high-resolution image of the canvas — drop it straight into an audit packet or your system security plan. The diagram is also summarised automatically in AllowNow's compliance report under Network Scope Inventory, listing each in-scope resource with its type, provider and CIDR.

7

Recertify annually

ongoing

Networks change. AllowNow tracks last reviewed on every Live diagram and surfaces it in Access Reviews → Scope Diagrams. When a diagram hasn't been reviewed in 12 months, it's flagged Review overdue and the owner gets a reminder email. Open it, confirm it still matches reality, and click Mark reviewed to stamp the reviewer and date.

Standard: PCI DSS Req. 1.2.3 requires the network diagram to be kept current and reviewed at least annually and after significant changes. SOC 2 and ISO 27001 auditors expect the same currency evidence.

Tips

  • Start at the boundary. Draw the network/subnet nodes first, then place instances and databases inside them — it keeps the in-scope perimeter obvious.
  • Use “in scope” deliberately. The flag drives both the report inventory and how a QSA reads the picture. Mark shared services (logging, monitoring) explicitly.
  • Re-export after every change. Whenever you edit a Live diagram, export a fresh PNG so your evidence pack matches the current state.

Turn your network into audit-ready evidence

AllowNow keeps your scope diagram, access reviews, and compliance reports in one place — current, attributed, and one click from an auditor-ready export.

Get started free