ISO 27001A.8 — Segregation of networks
A.8.22
Segregation of networks
ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026
Objective
Segregate groups of information services, users, and information systems on networks as required by trust boundaries.
Points of focus
- Define trust zones
- Separate prod and non-prod
- Control cross-zone paths
- Review peering/sharing
Implementation notes
Separate accounts or VPCs for prod. No direct laptop-to-database paths — use bastion/ZTNA. Review VPC peering and shared services quarterly. Assign a named owner in the SoA, tie operating evidence to network architecture diagram, and sample the control during internal audit before Stage 2 fieldwork.
Audit tip: Walk the diagram and prove staging cannot reach prod data stores without controlled paths.
Evidence auditors typically request:
- Network architecture diagram
- VPC/subnet design docs
- Security group / firewall matrices
- Peering review tickets
Common gaps
- Shared VPC for prod and staging
- Developer laptops flat on prod subnet
- Over-permissive peering
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.8.22 | This control |
| SOC 2 | CC6.1, CC6.6 | Related SOC 2 themes (CC6.1, CC6.6) — map in your crosswalk; not identical requirements. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.8.22)
Frequently Asked Questions
Start with coarse prod/non-prod separation; deepen where risk warrants.
Still segregate accounts and restrict outbound/inbound identities.
Logical access and network security themes in CC6.
Even without owned data centers, segregation of networks still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.
Start with network architecture diagram, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.