Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Category: Technical Controls

Network Segmentation

Also known as: network zoning, subnetting
Simply put

Network segmentation is the practice of dividing a computer network into smaller, separated sections rather than running everything on one large, open network. Each section, often called a segment, zone, or subnet, functions as its own smaller network, with traffic between sections controlled by devices such as firewalls, switches, and routers. The general aim is to limit how freely traffic moves across the network, which can help contain problems and control access.

Formal definition

Network segmentation is an architectural approach that divides a larger network into multiple isolated segments or subnets, each operating as a distinct network zone. Separation and traffic control between zones are typically enforced using devices such as firewalls, switches, and routers, and by defining rules governing communication across segment boundaries. It is a security and network-design technique rather than a regulatory obligation in itself, though it may be adopted to support compliance objectives or contractual requirements; note that specific implementations (for example, subnetting versus more granular micro-segmentation) and their control effectiveness vary by architecture and are not detailed in the evidence provided here. Note that one source in the evidence packet describes segmentation in terms of directing email traffic, which is inconsistent with the network-architecture definitions given by the other sources; readers should verify terminology against current authoritative technical references.

Why it matters

Network segmentation matters because a flat, undivided network allows traffic to move freely between systems, which means that a compromise in one area can more easily reach others. By dividing a network into smaller, isolated zones with controlled communication across boundaries, organizations can limit the paths available to an attacker and contain problems within a segment rather than allowing them to spread across the entire environment. This containment principle is a core reason segmentation appears in security architecture discussions.

Segmentation is also relevant to compliance and contractual objectives, though it is important to be precise about its status. Network segmentation is a security and network-design technique, not a regulatory obligation in itself. Organizations may adopt it to support compliance goals or to satisfy contractual requirements, but the specific effectiveness of any implementation depends on the underlying architecture and control design, which are fact-specific and not detailed in the evidence available here.

Because the effectiveness and granularity of segmentation vary considerably across approaches, readers should not assume that dividing a network automatically satisfies a given standard or regulatory expectation. Application to particular circumstances requires professional judgment, and terminology and control frameworks should be verified against current authoritative technical references.

Who it's relevant to

Information security professionals
Security teams responsible for network architecture may use segmentation to isolate zones and control traffic between them, limiting how freely a compromise can spread. The choice of implementation and its control effectiveness are architecture-specific and require professional judgment.
Network architects and engineers
Those designing network topology work directly with the division of a network into segments or subnets and the placement of firewalls, switches, and routers that enforce boundaries between zones. Design decisions determine the granularity and enforcement of separation.
Compliance and audit personnel
Compliance officers and auditors may encounter segmentation as a control adopted to support compliance objectives or contractual requirements. Because segmentation is a technique rather than a regulatory obligation in itself, its role in meeting any specific standard should be assessed against the applicable requirements and verified against current authoritative sources.

Inside Network Segmentation

Segmentation
The practice of dividing a network into distinct zones or subnetworks so that traffic between them can be controlled, monitored, and restricted. It limits the lateral movement of an attacker who gains access to one part of the environment and helps contain the scope of a compromise.
Microsegmentation
A more granular approach that applies segmentation controls at the level of individual workloads, applications, or hosts rather than broad network zones. It is commonly associated with software-defined and cloud environments, though implementation approaches and terminology continue to evolve.
Segmentation Controls
The technical mechanisms that enforce separation, which may include firewalls, access control lists, virtual LANs (VLANs), routing rules, and policy-based controls. The appropriate mix generally depends on the architecture, risk level, and data categories involved.
Trust Zones
Logical groupings of systems that share a common security posture or sensitivity level, such as separating systems that process regulated data from general corporate networks. Defining zones is typically a prerequisite to designing effective segmentation.
Scope Reduction
The use of segmentation to isolate systems handling sensitive or regulated data so that only those systems, rather than the entire network, fall within the boundary being assessed or audited. This is a common driver where contractual or sector frameworks reward narrowing the environment under review.

Common questions

Answers to the questions practitioners most commonly ask about Network Segmentation.

Is network segmentation a legal requirement under regulations like the GDPR or HIPAA?
Network segmentation is generally best understood as a security control or technique rather than an explicitly mandated legal requirement in most data protection regulations. Instruments such as the GDPR (EU) and HIPAA (US healthcare sector) typically require appropriate technical and organizational measures proportionate to risk, without prescribing segmentation by name. Segmentation may be one way an organization implements such measures, and certain contractual frameworks (for example the PCI DSS, a contractual standard applied by the payment card industry) treat it more directly as a scoping mechanism. Whether it is expected in a given case depends on the applicable rules, risk level, and data categories involved. Verify specific obligations against the current authoritative text and any applicable contractual requirements.
Does implementing network segmentation mean an organization is compliant or certified?
No. Implementing network segmentation is a technical measure, not the same as achieving compliance or certification. Compliance refers to meeting the obligations that apply to an organization, and certification refers to a formal attestation by an accredited body against a defined scheme or standard. Segmentation may contribute to demonstrating that appropriate controls are in place, but on its own it does not establish that an organization satisfies a regulation's requirements or holds any certification. Those outcomes depend on the full set of controls, documentation, and, where relevant, independent audit or assessment. Application to a particular situation requires professional judgment.
How does network segmentation affect the scope of a PCI DSS assessment?
Segmentation is commonly used to reduce the portion of an environment that falls within scope for a PCI DSS assessment by isolating systems that store, process, or transmit cardholder data from the rest of the network. In principle, systems that are effectively segmented from the in-scope environment may be excluded from certain requirements. The adequacy of that isolation generally must be validated, and the standard's specific provisions and versions change over time. Organizations should confirm current scoping expectations against the latest official PCI DSS documentation and, where applicable, with their assessor.
What is the difference between logical and physical segmentation in practice?
Physical segmentation separates networks using distinct hardware and physical connections, while logical segmentation uses configuration-based controls such as VLANs, access control lists, or firewall rules to separate traffic on shared infrastructure. Logical approaches are often more flexible and cost-effective, whereas physical separation may be preferred where stronger isolation is desired. The appropriate choice generally depends on risk, sensitivity of the data, and operational constraints, and the effectiveness of either approach depends on correct configuration and ongoing maintenance rather than the method alone.
How can the effectiveness of network segmentation be verified?
Effectiveness is typically evaluated through methods such as configuration review, penetration testing, and traffic analysis to confirm that controls actually prevent unauthorized communication between segments. Note the distinction between an assessment, which is generally an internal or advisory evaluation of controls, and an audit, which is usually a more formal examination against defined criteria. Because misconfiguration and configuration drift can undermine segmentation over time, verification is generally treated as a recurring activity rather than a one-time exercise. The specific testing expected may depend on applicable standards or contractual terms.
Does network segmentation support privacy obligations or only security objectives?
Segmentation is primarily a security measure that can also support privacy objectives, but the two remain distinct concepts. Security focuses on protecting the confidentiality, integrity, and availability of systems and data, while privacy concerns how personal data is collected, used, and governed. By limiting the systems that can reach sensitive personal data, segmentation may help implement principles such as access limitation and data minimization in practice. It does not by itself address broader privacy obligations such as lawful basis, transparency, or individual rights, which require separate measures. Application to specific circumstances requires professional judgment.

Common misconceptions

Network segmentation is a legal requirement mandated by regulations such as the GDPR.
Segmentation is generally a security control and design practice rather than an explicit statutory mandate. Broad data protection regulations tend to require appropriate technical and organizational measures without prescribing segmentation by name, while certain sector or contractual frameworks may reference or reward it. Whether it is required in a given case is fact-specific and depends on the applicable obligations, so readers should verify against the relevant authoritative text.
Segmentation and microsegmentation are interchangeable terms for the same thing.
They are related but distinct. Segmentation typically refers to broader network zones enforced by controls such as VLANs and firewalls, whereas microsegmentation applies more granular, often workload-level controls. Treating them as identical can lead to misjudging the granularity of protection actually in place.
Once a network is segmented, systems in isolated zones are secure and no longer need other controls.
Segmentation is one control that limits lateral movement and reduces scope; it is not a complete security solution. It does not replace access management, monitoring, patching, or other measures, and its effectiveness depends on how well the controls are configured and maintained over time.

Best practices

Define trust zones based on data sensitivity and risk before designing controls, so that segmentation reflects the actual categories of data and systems being protected.
Select segmentation controls appropriate to the architecture, combining mechanisms such as firewalls, access control lists, and VLANs rather than relying on a single technique.
Where scope reduction is a goal, document how segmentation isolates the systems handling sensitive or regulated data and confirm the boundary against the specific framework or contractual requirements that apply.
Regularly review and test segmentation controls to confirm that isolation actually holds, since misconfiguration can quietly undermine intended separation.
Treat segmentation as one layer among several, maintaining complementary controls such as access management, monitoring, and patching within each zone.
Verify the applicability and terminology of segmentation and microsegmentation requirements against the latest authoritative sources, as frameworks, versions, and interpretations change over time.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.