Microsegmentation moves boundaries closer to workloads
Instead of a handful of large zones, microsegmentation puts policy between individual workloads.
The benefit is precision: this service may talk to that database and nothing else. The cost is that you now need to know, accurately, what talks to what, which most organisations do not. The discovery work is the project. The enforcement is comparatively easy once the map exists.
More on Network segmentation
- Segmentation limits paths, not compromise itselfBulkheads, not armour
- Every firewall allow rule creates a permitted pathEvery rule is a hole
- Flat networks turn local trust into broad reachabilityOne floor, no walls
- Management paths can bypass segmentationOver the checkpoint
- Default deny makes new paths deliberateNothing moves until a lever is pulled
- Network zones should reflect trust and functionZones follow the job
