Network zones should reflect trust and function
Zones drawn around what things do and how much they are trusted are useful. Zones drawn around where the cables happened to go are not.
Legacy segmentation often reflects office floors, acquisitions or historical accidents, which means the boundaries do not correspond to anything meaningful about risk. Redrawing them around function is disruptive and is the difference between segmentation that constrains an attacker and segmentation that merely complicates a diagram.
More on Network segmentation
- Segmentation limits paths, not compromise itselfBulkheads, not armour
- Every firewall allow rule creates a permitted pathEvery rule is a hole
- Flat networks turn local trust into broad reachabilityOne floor, no walls
- Microsegmentation moves boundaries closer to workloadsMove the fence inwards
- Management paths can bypass segmentationOver the checkpoint
- Default deny makes new paths deliberateNothing moves until a lever is pulled
