Default deny makes new paths deliberate
Starting from "nothing is allowed" and adding what is needed produces a very different result from starting permissive and blocking problems.
The rules end up describing what the business actually does, and anything new requires a deliberate decision by somebody. It is more work at the beginning and far less over time, because the alternative accumulates permissions nobody remembers granting and nobody dares remove.
More on Network segmentation
- Segmentation limits paths, not compromise itselfBulkheads, not armour
- Every firewall allow rule creates a permitted pathEvery rule is a hole
- Flat networks turn local trust into broad reachabilityOne floor, no walls
- Microsegmentation moves boundaries closer to workloadsMove the fence inwards
- Management paths can bypass segmentationOver the checkpoint
- Network zones should reflect trust and functionZones follow the job
