Microsegmentation

Microsegmentation is a fine-grained form of network segmentation in which security rules are applied down to individual workloads, applications or services. Instead of separating entire network areas from one another, it is defined for each communication relationship whether it is permitted.

Microsegmentation is mostly implemented in software: via agents on servers and endpoints, via functions of hypervisors and container platforms, or via security groups in cloud environments. The rules are based on the identity, application and role of a system rather than on IP addresses and remain valid when workloads are moved. The prerequisite is precise knowledge of the communication relationships, which many tools establish by visualizing the traffic.

Compared with classic Network Segmentation with a few coarse zones, microsegmentation above all limits the lateral movement of attackers within a segment. NIST publication SP 800-207 names microsegmentation as one way of implementing a zero trust architecture. It is thus a central building block of Zero Trust and complements Cloud Security with the isolation of dynamic workloads.