Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 8.22

Segregation of Networks: A Practical Implementation Guide

Separate users, systems and services into zones that limit unauthorized access and incident spread.

This control concerns segregating groups of information services, users and systems in networks.

Practical interpretation: Segmentation should follow trust, sensitivity and communication need. VLANs alone do not help if routing permits unrestricted traffic.

What should the control achieve?

  • Network zones reflect risk and function.
  • Allowed flows are explicit and minimal.
  • High-risk management and guest paths are separated.
  • Segmentation is tested and monitored.

Step-by-step implementation

1

Define zone model

Group production, user, development, management, guest, supplier and high-sensitivity assets.

2

Map required flows

Document source, destination, service, owner and business reason.

3

Enforce boundaries

Use firewalls, cloud policies, proxies, microsegmentation and identity-aware controls.

4

Separate administration

Protect management planes and privileged workstations.

5

Control temporary paths

Expire project, migration and vendor connectivity.

6

Test isolation

Use rule review, scanning and penetration testing.

What this could look like in practice

Production databases accept traffic only from approved application services and management hosts. User laptops cannot connect directly. Guest wireless is internet-only, and vendor access is time-limited.

ActivityPractical implementationEvidence
Zone designRisk and function define boundaries.Architecture
Flow approvalApplication owner approves specific service.Rule ticket
Temporary connectionMigration path has expiry and monitoring.Exception
Isolation testScanning verifies prohibited paths fail.Test report

Implementation evidence

  • Segmentation standard
  • Zone diagrams
  • Flow matrix
  • Firewall configuration
  • Rule approvals
  • Temporary-access records
  • Isolation tests
  • Monitoring alerts

Useful metrics

  • Any-to-any rules
  • Temporary paths past expiry
  • Segmentation test failures
  • Critical assets in wrong zones

Common mistakes

  • Creating VLANs without restrictive routing.
  • Placing management interfaces with users.
  • Permanent vendor tunnels.
  • Ignoring cloud security groups and service meshes.
  • No validation of actual reachability.

Questions an auditor may ask

  • How are zones defined?
  • Which flows are permitted?
  • How is management traffic separated?
  • Show an isolation test.
Implementation test: From representative zones, attempt permitted and prohibited connections and compare results with the approved flow matrix.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.