Skip to content

Micro-Segmentation

What is Micro-Segmentation?

A security technique that divides a network into small, isolated segments with individual security policies to limit lateral movement and contain breaches.

Information Security

What the standards actually require on micro-segmentation

Requirements naming micro-segmentation across 4 standards, quoted from the control text.

Where workload to workload control is the primary concern, deploy micro segmentation that places each resource or small group of resources behind its own gateway. Use software defined controls rather than relying on VLAN topology.

SP800-207-4.2 · Micro Segmentation Deployment

Move from perimeter-based segmentation to micro-segmentation enforced by identity and policy.

ZTMM-NET-1 · Network Segmentation
FISMA1 control

FISMA coordination with CIRCIA + Zero Trust + Executive Orders + OMB Memoranda. CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act of 2022): Final Rule effective 2026;

FISMA-CIRCIA-ZTA-EO14028 · CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda
HKMA TM-G-11 control

HKMA TM-G-1 Information Security Programme. Comprehensive technical + administrative + physical security controls. (1) INFORMATION SECURITY PROGRAMME (TM-G-1.6.1) - documented + Board-approved information security programme + governance + roles + ISMS-style al...

HKMA-TMG1-InfoSec-Access-PAM-Network-Crypto-DLP-Endpoint · TM-G-1 Information Security Programme + Access + PAM + Network + Crypto + DLP + Vulnerability + Endpoint

Questions people ask about micro-segmentation

What is Micro-Segmentation?
A security technique that divides a network into small, isolated segments with individual security policies to limit lateral movement and contain breaches.
Why is Micro-Segmentation important for compliance?
Micro-Segmentation is a key concept in Information Security. Understanding micro-segmentation helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Micro-Segmentation?
Micro-Segmentation appears in the requirement text of NIST SP 800-207, CISA Zero Trust Maturity Model, FISMA, HKMA TM-G-1. Across these standards we have identified 4 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Micro-Segmentation?
Explore our compliance framework pages to see how micro-segmentation applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Micro-Segmentation applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.