ISO 27001 Annex A 8.22 requires network segregation into separate security perimeters. You must manage this through documented processes in SharePoint or Confluence. Boundaries should isolate sensitive traffic from untrusted areas. This control prevents unauthorised access across the network. Internal repositories provide the required oversight.
Table of contents
Key Takeaways
- Define Network Perimeters: Establish clear perimeter boundaries separating core corporate systems, development environments, guest access, and high-risk data zones.
- Document Architecture Maps: Maintain up-to-date network topology and segmentation diagrams in Confluence to visualize traffic flows and boundary controls.
- Implement Virtual Local Networks: Configure VLANs and subnets to logically isolate groups of systems based on business criticality and security classification.
- Enforce Access Control Lists: Apply strict firewalls, gateway rules, and access control lists (ACLs) to regulate and filter all cross-zone network traffic.
- Restrict Cross-Boundary Access: Permit traffic across network perimeters only when explicitly required by documented business needs and formal change approvals.
- Isolate Untrusted Networks: Keep guest Wi-Fi networks and untrusted external connections completely segregated from internal networks and sensitive databases.
- Monitor Boundary Gateways: Collect and review traffic logs and access events at perimeter firewalls to detect unauthorized cross-zone access attempts.
- Audit Rulesets Periodically: Conduct regular reviews of perimeter filtering rules and network boundary definitions to prevent unauthorized perimeter drift.
How to Implement ISO 27001 Annex A 8.22 Segregation of Networks
- Document Network Topology: Create and maintain current network architecture maps in Confluence detailing all VLANs, subnets, and security perimeters.
- Maintain Version-Controlled Repositories: Store approved network diagrams and boundary definitions in a version-controlled SharePoint library.
- Draft Perimeter Access Rules: Define specific filtering policies and access rules for each network zone boundary within SharePoint policies.
- Align Controls with Risk: Link boundary restrictions and segregation rules directly to identified asset risks in your organizational risk register.
- Schedule Monthly Isolation Audits: Set up recurring Jira workflows to track, execute, and verify monthly network isolation checks.
- Enforce Change Management: Route all firewall adjustments, VLAN reconfigurations, and cross-zone routing requests through Jira change tickets.
- Isolate Guest and Development Zones: Configure dedicated VLANs and firewalls to keep untrusted guest Wi-Fi and development environments strictly separated from production databases.
- Centralize Boundary Traffic Logs: Direct all perimeter firewall logs and cross-zone traffic alerts to a central logging repository for active monitoring.
How to Audit ISO 27001 Annex A 8.22 Segregation of Networks
- Inspect Network Segregation Policies: Review the network segregation policy in SharePoint to verify that mandatory isolation rules between corporate, production, development, and guest networks are formally defined.
- Verify Network Architecture Diagrams: Examine current network topology maps and Confluence documentation to confirm VLAN boundaries, subnet ranges, and security perimeters match live configurations.
- Sample Firewall Rule Configurations: Inspect active Access Control Lists (ACLs) and firewall rules on core routers and security gateways to confirm cross-zone traffic is blocked by default.
- Test Inter-Zone Boundary Rules: Audit rule configurations for approved cross-boundary connections (e.g., API gateways, jump hosts) to verify traffic is strictly filtered, authenticated, and logged.
- Inspect Wireless Network Separation: Verify that corporate, guest, and IoT wireless networks run on isolated SSIDs with strict VLAN separation preventing access to internal resources.
- Audit Cloud Network Boundaries: Review AWS Security Groups, Azure Virtual Networks (VNets), and VPC peering configurations to verify segregation controls extend across cloud environments.
- Check Segregation Incident Logs: Sample central log streams to confirm unauthorized attempts to traverse network boundaries trigger real-time security alerts.
- Examine Periodic Boundary Review Records: Check meeting minutes and technical review logs in internal repositories to confirm network segregation rules and cross-zone permissions are evaluated regularly.
- Verify Administrative Control Isolation: Confirm that administrative access pathways (e.g., SSH, RDP) across zone boundaries require dedicated, multi-factor authenticated jump hosts or bastion servers.
- Inspect Legacy System Micro-segmentation: Audit legacy or out-of-support infrastructure to ensure it is isolated in dedicated, strictly filtered network segments with no direct outbound internet pathways.
Audit Evidence Checklist
- Network Perimeters Diagrams: Present version-controlled topology maps stored in Confluence clearly illustrating VLAN boundaries, subnet ranges, and security perimeters.
- Firewall Change Management Logs: Provide full Jira ticket history for inter-zone firewall rule adjustments showing risk assessments, technical reviews, and authorization sign-offs.
- Management Risk Review Minutes: Share formal leadership meeting minutes in SharePoint demonstrating regular evaluation of network segregation risks and boundary controls.
- VLAN and Subnet Configurations: Produce technical exports or baseline configuration logs stored in SharePoint detailing active VLAN assignments and access control list (ACL) rulesets.
- Internal Isolation Audit Reports: Produce documented internal audit findings and penetration test summaries verifying zero unauthorized cross-boundary traffic across network zones.
- Wireless Network Isolation Proof: Provide SSIDs and technical configuration exports showing strict VLAN separation between corporate systems, guest Wi-Fi, and IoT devices.
- Cloud Network Security Group Rulesets: Supply exported AWS Security Group, Azure VNet, or VPC peering rules showing enforced micro-segmentation across cloud environments.
What to Teach Employees
- Understand Network Segregation: Teach staff why corporate, production, development, and guest environments are isolated into separate network zones to protect sensitive data.
- Use Designated SSIDs: Show employees how to connect personal devices strictly to the isolated guest Wi-Fi and never to internal corporate Wi-Fi networks.
- Access Production Safely: Train developers and system admins to access production zones only through authorized jump hosts and secure, MFA-protected bastions.
- Avoid Bridging Networks: Explain why connecting a single device simultaneously to multiple networks (such as ethernet and Wi-Fi) bypasses perimeter boundaries.
- Respect Environment Boundaries: Remind technical staff never to transfer live production customer data into unsegmented development or test environments.
- Follow Gateway Request Workflows: Train engineers to route all requests for cross-zone communications or new API endpoints through formal change approvals.
- Report Unauthorized Zone Access: Teach employees to notify IT security immediately if they encounter unexpected network paths or access rights across zones.
- Protect Cloud Segregation Rules: Show cloud admins why keeping AWS Security Groups and Virtual Private Clouds (VPCs) strictly isolated prevents unauthorized lateral movement.
- Maintain Separation of Admin Protocols: Instruct network operators never to expose management access protocols directly to general user segments or public networks.
Common Implementation Challenges
- Legacy Application Dependencies: Older software architectures often rely on unencrypted, direct database connections that cross network boundaries, making strict VLAN segregation difficult without breaking functionality.
- Overly Permissive Exceptions: Operational pressure to solve connectivity issues during deployment often results in blanket “allow all” rules across zone boundaries that are rarely cleaned up later.
- Dual-Homed Device Risks: Workstations or servers simultaneously connected to wired corporate networks and wireless or VPN networks create unintended bridging paths that bypass boundary controls.
- Cloud Environment Complexity: Managing multi-cloud Virtual Private Clouds (VPCs), subnets, and security groups across AWS, Azure, or GCP can lead to misconfigurations and accidental cross-zone exposure.
- Developer Workflows Friction: Strict isolation of staging and development zones from production APIs can hinder developer productivity, leading staff to seek unauthorized workarounds or jump hosts.
- Incomplete IoT and Guest Isolation: Smart office devices, printers, and guest Wi-Fi networks are frequently assigned to corporate subnets due to setup oversights, creating lateral movement vectors.
- Documentation Lag: Network boundary changes made during emergency maintenance are often not updated in Confluence topology maps, leaving security teams with an inaccurate view of live zone perimeters.
- Monitoring Cross-Zone Traffic: High volumes of inter-zone traffic can generate excessive log data, making it challenging for central log tools to isolate genuine breach attempts from authorized traffic.
How to Measure Effectiveness (KPIs)
- Unauthorized Zone Crossing Count: Tracks the number of detected attempts to traverse network boundaries or bypass access control lists without authorization.
- Boundary Exception Rule Audit Rate: Measures the percentage of cross-zone firewall rules and API gateway exceptions reviewed and revalidated every three months.
- Isolated Segment Coverage Rate: Tracks the percentage of active subnets, cloud VPCs, and guest networks that comply with strict segregation baselines.
- Dual-Homed Endpoint Incident Count: Measures instances where devices simultaneously connected to multiple networks (e.g., corporate and guest/untrusted) were flagged and disconnected.
- Mean Time to Contain Zone Breaches: Measures the average time required by technical teams to isolate and block lateral movement during a boundary security event.
- Unapproved Port and Protocol Detection Rate: Tracks the percentage of unauthorized ports or protocols flagged traversing perimeter boundaries between production and non-production environments.
- Cloud Security Group Micro-segmentation Audit Rate: Measures the percentage of AWS Security Groups, Azure VNets, or GCP subnets reviewed quarterly for stale cross-zone access permissions.
- Network Topology Drift Percentage: Tracks the variance between live network subnets/VLANs and the documented architecture maps maintained in Confluence.
Related ISO 27001 Controls
Annex A 8.22 depends on several core organisational dependencies:
- ISO 27001 Annex A 8.20: Directs the security of network services.
- ISO 27001 Annex A 8.21: Governs network security controls.
- ISO 27001 Clause 8.1: Operational planning and control of boundaries.


