ISO/IEC 27001:2022 Annex A · Control 8.22
Segregation of Networks: A Practical Implementation Guide
Separate users, systems and services into zones that limit unauthorized access and incident spread.
This control concerns segregating groups of information services, users and systems in networks.
What should the control achieve?
- Network zones reflect risk and function.
- Allowed flows are explicit and minimal.
- High-risk management and guest paths are separated.
- Segmentation is tested and monitored.
Step-by-step implementation
Define zone model
Group production, user, development, management, guest, supplier and high-sensitivity assets.
Map required flows
Document source, destination, service, owner and business reason.
Enforce boundaries
Use firewalls, cloud policies, proxies, microsegmentation and identity-aware controls.
Separate administration
Protect management planes and privileged workstations.
Control temporary paths
Expire project, migration and vendor connectivity.
Test isolation
Use rule review, scanning and penetration testing.
What this could look like in practice
Production databases accept traffic only from approved application services and management hosts. User laptops cannot connect directly. Guest wireless is internet-only, and vendor access is time-limited.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Zone design | Risk and function define boundaries. | Architecture |
| Flow approval | Application owner approves specific service. | Rule ticket |
| Temporary connection | Migration path has expiry and monitoring. | Exception |
| Isolation test | Scanning verifies prohibited paths fail. | Test report |
Implementation evidence
- Segmentation standard
- Zone diagrams
- Flow matrix
- Firewall configuration
- Rule approvals
- Temporary-access records
- Isolation tests
- Monitoring alerts
Useful metrics
- Any-to-any rules
- Temporary paths past expiry
- Segmentation test failures
- Critical assets in wrong zones
Common mistakes
- Creating VLANs without restrictive routing.
- Placing management interfaces with users.
- Permanent vendor tunnels.
- Ignoring cloud security groups and service meshes.
- No validation of actual reachability.
Questions an auditor may ask
- How are zones defined?
- Which flows are permitted?
- How is management traffic separated?
- Show an isolation test.
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.