I've never had to place an HSM on a network before so I want to ask this question to get a consensus on best practice for this.
The HSM will reside on an internal network which will look like this;
internet <-> boundary firewall <-> DMZ <-> inside FW <-> IPS <-> internal network
The inside firewall will also have a secondary connection to our corporate WAN and the internal network will be used for Dev/Pre-Prod etc.
Obviously I will be segmenting the internal network into different confidentiality/security levels, therefore the HSM will reside in it's own subnet. Would it be best to place a further FW at the ingress/egress point of the subnet for the HSM? should I have an IPS.
Any pointers from someone who has implemented an HSM on a network would be appreciated.