← ISO 27001 · A.8 — Technological

A.8.22 — Segregation of networks

medium network-securitysegregation

Requirement

Groups of information services, users and information systems shall be segregated in the organisation's networks.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
segmentsegregat…vlansubnetvpcisolationsegmentationisolat…
Supporting terms — specificity signals
dmzprivate subnetsecurity groupzero trustmicrosegmentationenvironment separation

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
PCI DSS 4.0.1 1.3 Restrict network access to and from the cardholder data environment network-security segregation
NIST CSF 2.0 PR.IR-01 Networks and environments are protected from unauthorised logical access network-security segregation
SOC 2 CC6.6 Boundary protection network-security
PCI DSS 4.0.1 1.2 Network security control configuration and review network-security
PCI DSS 4.0.1 1.4 Controls between trusted and untrusted networks network-security
PCI DSS 4.0.1 6.4.1-6.4.2 Public-facing web applications are protected against attacks network-security
PCI DSS 4.0.1 6.5 Change management and separation of environments segregation
NIST CSF 2.0 PR.DS-02 Confidentiality, integrity and availability of data in transit network-security