Skip to content
compliancebase
ISO 27001A.8 — Segregation of networks

A.8.22

Segregation of networks

ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026

Objective

Segregate groups of information services, users, and information systems on networks as required by trust boundaries.

Points of focus

  • Define trust zones
  • Separate prod and non-prod
  • Control cross-zone paths
  • Review peering/sharing

Implementation notes

Separate accounts or VPCs for prod. No direct laptop-to-database paths — use bastion/ZTNA. Review VPC peering and shared services quarterly. Assign a named owner in the SoA, tie operating evidence to network architecture diagram, and sample the control during internal audit before Stage 2 fieldwork.

Audit tip: Walk the diagram and prove staging cannot reach prod data stores without controlled paths.

Evidence auditors typically request:

  • Network architecture diagram
  • VPC/subnet design docs
  • Security group / firewall matrices
  • Peering review tickets

Common gaps

  • Shared VPC for prod and staging
  • Developer laptops flat on prod subnet
  • Over-permissive peering

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.8.22This control
SOC 2CC6.1, CC6.6Related SOC 2 themes (CC6.1, CC6.6) — map in your crosswalk; not identical requirements.

Primary sources

Frequently Asked Questions

Start with coarse prod/non-prod separation; deepen where risk warrants.

Still segregate accounts and restrict outbound/inbound identities.

Logical access and network security themes in CC6.

Even without owned data centers, segregation of networks still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.

Start with network architecture diagram, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: August 2026 · Primary sources linked above