Skip to content

Network Segmentation

What is Network Segmentation?

The practice of dividing a computer network into smaller subnetworks to improve security and performance. Segmentation limits the blast radius of security incidents and restricts access to sensitive resources.

Information Security

Each of these is named in at least one of the same controls as network segmentation. The number is how many controls name both.

What the standards actually require on network segmentation

Requirements naming network segmentation across 6 standards, quoted from the control text.

IEC 624433 controls

The IACS shall provide the capability to logically segment networks and restrict data flow between zones based on the principle of least communication necessary.

62443-3-3-FR5-SR-5-1 · Network Segmentation (FR5 Restricted Data Flow)

Segment IT and OT networks using firewalls, DMZs, and unidirectional gateways where feasible.

AWWA-G430-4 · Network Segmentation IT/OT

Move from perimeter-based segmentation to micro-segmentation enforced by identity and policy.

ZTMM-NET-1 · Network Segmentation
NIST SP 800-1902 controls

Virtual network segmentation. Control from NIST SP 800-190 framework, domain: NIST SP 800-190: Cloud Infrastructure Security.

NIST190-16 · Virtual network segmentation

Per TSA SD: segmentation. Requirements include (a) OT/IT Network Segmentation + (b) Access Control + privileged access + (c) maintain documented network architecture.

TSAPIPE-2 · OT/IT Network Segmentation and Access Control

Questions people ask about network segmentation

What is Network Segmentation?
The practice of dividing a computer network into smaller subnetworks to improve security and performance. Segmentation limits the blast radius of security incidents and restricts access to sensitive resources.
Why is Network Segmentation important for compliance?
Network Segmentation is a key concept in Information Security. Understanding network segmentation helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Network Segmentation?
Network Segmentation appears in the requirement text of IEC 62443, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), CISA Zero Trust Maturity Model, IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1), NIST SP 800-190. Across these standards we have identified 13 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Network Segmentation?
Explore our compliance framework pages to see how network segmentation applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Network Segmentation applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.