ISO 27002:2022
Technological controls – ISO 27002:2022

ISO 27002:2022 8.22: Segregation of networks

Within its networks the organization is to keep groups of users, information services and information systems apart. Purpose: divide the network along security boundaries and control traffic between them according to business need. Guidance: consider managing large networks by splitting them into separate domains, each kept apart from the internet. Domains can be based on trust, criticality and sensitivity (for example public access, desktop and server domains, or low- and high-risk systems), on organizational units such as HR, finance or marketing, or on a mix, such as a server domain serving several units, and can be built with physically separate or logically separate networks. Each domain has a well-defined perimeter; where traffic between domains is allowed it passes through a gateway such as a firewall or filtering router. The criteria for dividing domains and the access permitted through gateways come from assessing each domain's security requirements against the access control policy (5.15), access needs and the value and classification of the information, taking into account the cost and performance impact of the gateway technology. Wireless networks need special handling because their perimeter is poorly defined: consider adjusting radio coverage, and in sensitive environments treat all wireless access as external, keeping it apart from internal networks until it has passed a gateway that applies the network controls (8.20). Guest wireless should be separated from staff wireless where staff use only controlled, policy-compliant devices, and guest WiFi should be at least as restricted as staff WiFi to discourage staff from using it. Other information: networks often extend beyond the organization through partnerships and shared facilities, raising the risk of unauthorized access to systems that need protecting from other network users.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 99 controls across 36 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 12 controls

  • 1.2.3 1.2.3 Accurate network diagram of CDE connections
  • 1.2.4 1.2.4 Accurate data-flow diagram for account data
  • 1.3.1 1.3.1 Inbound CDE traffic restricted
  • 1.3.3 1.3.3 NSCs between wireless networks and the CDE
  • 1.4.1 1.4.1 NSCs between trusted and untrusted networks
  • 1.4.2 1.4.2 Restricting traffic entering trusted networks from outside
  • 1.4.4 1.4.4 Cardholder data stores not reachable from untrusted networks
  • 1.4.5 1.4.5 Internal IP and routing disclosure limited
  • 1.5.1 1.5.1 Security controls on dual-connected devices
  • 11.4.5 11.4.5 Annual segmentation penetration testing
  • 12.5.2 12.5.2 Annual and change-driven scope confirmation
  • 8.2.3 8.2.3 Service provider unique factors per customer

FedRAMP High · 8 controls

  • AC-4 Information Flow Enforcement
  • AC-4(21) Physical or Logical Separation of Information Flows
  • CM-7(1) Periodic Review
  • SC-15 Collaborative Computing Devices and Applications
  • SC-22 Architecture and Provisioning for Name/Address Resolution Service
  • SC-7 Boundary Protection
  • SC-7(18) Boundary Protection | Fail Secure (SC-7(18))
  • SC-7(5) Deny by Default Allow by Exception

FedRAMP Moderate · 8 controls

  • AC-4 Information Flow Enforcement
  • AC-4(21) Physical or Logical Separation of Information Flows
  • CM-7(1) Periodic Review
  • SC-15 Collaborative Computing Devices and Applications
  • SC-22 Architecture and Provisioning for Name/Address Resolution Service
  • SC-7 Boundary Protection
  • SC-7(18) Boundary Protection | Fail Secure (SC-7(18))
  • SC-7(5) Deny by Default Allow by Exception
  • ISM-0536 Segregating public wireless networks
  • ISM-0556 Workstations connected to phones and video units
  • ISM-1181 Network zones by criticality
  • ISM-1182 Restricting traffic between network segments
  • ISM-1385 Segregation of administrative infrastructure
  • ISM-1457 High assurance switches between SECRET domains
  • ISM-1461 Shared hardware for SECRET and TOP SECRET environments

NIST SP 800-53 Rev 5 · 7 controls

C5 (Germany) · 5 controls

  • C5-COS-02 Security requirements for connections in the Cloud Service Provider's network
  • C5-COS-03 Monitoring of connections in the Cloud Service Provider's network
  • C5-COS-05 Networks for administration
  • C5-COS-06 Segregation of data traffic in jointly used network environments
  • C5-OPS-24 Separation of Datasets in the Cloud Infrastructure
  • ANSSI-HYG-19 Segment the Network and Partition the Zones
  • ANSSI-HYG-20 Secure Wi-Fi Access Networks and Separate Usage
  • ANSSI-HYG-23 Partition Internet Facing Services from the Rest of the Information System
  • ANSSI-HYG-28 Use a Dedicated and Partitioned Network for Administration

CIS Controls v8 · 4 controls

  • CIS-12.2 Establish and Maintain a Secure Network Architecture
  • CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work
  • CIS-13.4 Perform Traffic Filtering Between Network Segments
  • CIS-3.12 Segment Data Processing and Storage Based on Sensitivity

CMMC 2.0 · 4 controls

SOC 2 · 4 controls

  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary
  • SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal
  • ASBv3-GS-2 Define and implement enterprise segmentation/separation of duties strategy
  • ASBv3-NS-9 Connect on-premises or cloud network privately
  • NS-1 Establish network segmentation boundaries

MTCS (Singapore) · 3 controls

  • 24.2 Multi tenancy
  • 24.3 Supporting infrastructure segmentation
  • A.22 Disclosure: Multi-tenancy
  • B.1.4 B.1.4 Security convergence of physical and information security risk management
  • B.6.2 B.6.2 Video system architecture

IEC 62443 · 2 controls

  • 62443-2-1-NSEG Network Segmentation and Zone/Conduit Implementation
  • 62443-3-2-ZCR-3 Partition the SUC into Zones and Conduits

ISO 27001:2022 · 2 controls

  • 8.20 Networks security
  • 8.22 Segregation of networks
  • 11.7.30.C.03 11.7.30.C.03 Network design elements for isolating access card systems
  • 22.2.14.C.01 22.2.14.C.01 Trust zones or domains in classified virtual architecture
  • P1-2.1.3 P1-2.1.3 Physical or logical limits between trusted and untrusted zones
  • P2-6.2.2 P2-6.2.2 Non-console HSM access originates only from the 3DE
  • ASD37-22 Network segmentation (Excellent)
  • AUCDR-IS-2 Secure the network and systems within the data environment

HIPAA Security Rule · 1 control

ISO/IEC 27011:2024 · 1 control

  • 27011-8.22 Segregation of Networks

ISO/IEC 27019:2024 · 1 control

  • ISO27019-13.1.3 Segregation of Networks

ISO/IEC 27043:2015 · 1 control

  • ISO27043-29 Segregation in networks

ISO/SAE 21434 · 1 control

  • ISO21434-29 Segregation in networks

NIS2 Directive · 1 control

  • Art.21.2.g Basic cyber hygiene practices and cybersecurity training
  • NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage

NIST SP 800-172 · 1 control

  • 3.13.1e Create Diversity in System Components to Limit Malicious Code Propagation
  • TSA-SD-05 Network segmentation between IT and OT

UK Cyber Essentials · 1 control

  • CE-SU.4 Remove Out-of-Support Software
  • MTSA-Network-Segmentation Network Segmentation Between IT and OT

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technological controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 8.22 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 99 it maps to, and the evidence behind each claim, over MCP and REST.