Network Segmentation
Network Segmentation is the division of a network into separate areas between which traffic is permitted only according to defined rules. The aim is to limit access to what is necessary and to make it harder for attacks and malware to spread within the network.
Technically, segmentation is implemented via virtual networks (VLANs), subnets, firewalls between the zones and access control lists (ACLs). Zones by protection need and function are common, such as a demilitarized zone (DMZ) for publicly reachable services and separate networks for production, administration, guests or operational technology. Regulations explicitly require segmentation: the German BSI IT-Grundschutz covers it in module NET.1.1, the IEC 62443 series for industrial networks in its zones and conduits model, and the payment card standard PCI DSS uses it to narrow the scope of assessment.
Classic segmentation works coarsely at the network level; fine-grained rules down to individual workloads are described by Microsegmentation. Because segmentation removes blanket trust in internal networks, it is regarded as a fundamental building block of Zero Trust.