Zones make policy enforceable
REF ACC-ZON-700OWNER Network DeskMODEL Declared zones
Access policy says who may reach what, but a flat network makes those words hard to enforce. Zoning turns the
policy into structure. We divide the estate into named zones with declared trust levels, define which zones may
speak to which, and route all crossing traffic through a point that inspects and records it.
For most organizations that means a user zone for everyday work, an administrative zone for management
activity, a service zone for shared systems, a data zone for the most sensitive stores, and a restricted zone for
industrial or operational technology where change windows are tight and traffic is unusual.
Rules that hold
REF ACC-ZON-720STYLE Explicit allowAUDIT Monthly
- Deny by default between zones. Movement is permitted only by an explicit rule with an owner, a
purpose and an expiry review date.
- Administration from a dedicated zone. Management interfaces are reachable only from the
administrative zone, never from the general user zone.
- Data stays where it is classified. Sensitive stores accept traffic from a narrow set of zones, and
the rules that allow it are reviewed more often than the rest.
- Third parties land in their own zone. Vendor and support access terminates in a zone with no direct
path to data, and any crossing is brokered and recorded.
- Operational technology is isolated thoughtfully. Industrial and building systems are separated with
the specific, minimal crossings their maintenance genuinely needs.
Documenting the map
REF ACC-ZON-740ARTEFACTS Map + rulesetREVIEW Quarterly
Every zone gets a one-page record: what it contains, its trust level, its owner, the rules that permit traffic
in and out, and the monitoring attached to it. Because the records are maintained as data rather than prose, we
can generate a current map on demand and flag rules that have outlived their purpose.
We also test the model. Where agreeably safe, we run controlled attempts to cross a boundary that policy says
should hold, and we log the result. A rule that has never been tested is a claim, and we prefer evidence.
Change without chaos
REF ACC-ZON-760WAVES Observation firstROLLBACK Retained
Segmentation projects fail when rules are switched on before anyone knows what traffic actually flows. We start
in observation mode, learn the real patterns, review them with your teams, and only then enforce. Changes are
made in small batches with rollback retained, and each batch is monitored for a defined period before the next
begins.
Deliverables · zone model, current and target maps, connection ruleset with owners, testing
record and quarterly review pack.
Zoning also has a human benefit. When the boundaries are written down and owned, a new engineer can tell where
a system belongs and who to ask before making a change. That shortens meetings, reduces the number of accidental
bridges between zones, and makes the estate easier to reason about at three in the morning when something is
wrong.
Where a crossing is genuinely needed, we keep it narrow and named rather than wide and anonymous. A single
rule for a single purpose, with an owner and a review date, is far easier to defend at audit than a broad
allowance nobody remembers approving.