Network segmentation is not just about physical and logical separation of your network elements, but also accounts, permissions, applications, files, and services that your enterprise relies on daily.  Begin with a current assessment of your environment.  Get the right people using the right tools to help map it out.  Ask why X talks to Y, if it should, and how to do so securely.  Update your diagrams and documentation, keeping them dynamic to match the evolving infrastructure.  Separating the elements from each other can mitigate the amount of damage caused deliberately or accidentally.  Test all configurations and use change controls.

Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out /  Change )

Google+ photo

You are commenting using your Google+ account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s