A.8.22A.8 Technological controls

Segregation of networks

A.5EVIDENCEA.6EVIDENCEA.7EVIDENCEA.8EVIDENCECONTROL MAPA.8.22 Evidence MapPOLICY / CONTROL / EVIDENCE / REVIEW

Purpose

Split networks into separate security zones for groups of services, users and systems and control traffic between them.

How to meet this control

In short: Segregate groups of services, users and systems on networks.

  1. Step 01Divide the network into zones by trust and criticality, separating production, corporate, management and guest segments into distinct VLANs or VPCs
  2. Step 02Place firewalls or gateways between zones and permit only the traffic justified by a risk assessment and the access control policy
  3. Step 03Isolate the internet-facing perimeter, putting public services in a DMZ separate from internal systems
  4. Step 04Segregate guest WiFi from staff networks and apply at least equal restrictions, treating wireless as untrusted until it passes a gateway
  5. Step 05Use micro-segmentation or host firewalls for sensitive workloads so lateral movement is contained
  6. Step 06Review cross-zone rules periodically and remove paths no longer needed

Tip: Separate production, corporate and guest networks/VPCs.

What ISO 27002 says to cover

Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.

  • ›Divide large networks into separate domains based on trust, criticality or organisational unit
  • ›Separate internal domains from the public internet, physically or logically
  • ›Define each domain perimeter and control cross-domain access at a gateway such as a firewall
  • ›Base the access allowed through gateways on a risk assessment and the access control policy
  • ›Weigh the cost and performance impact when choosing gateway technology
  • ›Give wireless networks special treatment because their perimeter is hard to define
  • ›In sensitive settings, treat all wireless access as external until it passes through a gateway
  • ›Segregate guest WiFi from staff WiFi and apply at least equal restrictions to guest access

Audit evidence to keep

  • - Network segmentation diagram showing zones and gateways
  • - Firewall rules controlling traffic between segments
  • - Configuration separating guest WiFi from staff networks
  • - Evidence of DMZ or perimeter isolation for public services
  • - Review record of cross-zone access rules

Common mistakes

  • - Writing a policy but not operating the process
  • - Keeping evidence in personal folders where auditors cannot trace it
  • - Letting exceptions stay open with no owner or expiry date

Owner, cadence, and proof

Assign one accountable owner for A.8.22. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to all technological controls or see the requirements (clauses 4 to 10). To run this control with automation, read how AI manages controls.