Network segmentation review

Test whether the trust boundaries in the network are actually enforced by routing and policy.

Damocles Network Segmentation Review maps trust zones, routing, firewall enforcement and management paths to determine whether users, servers, cloud, OT, guest and restricted networks can communicate beyond the intended design.

Trust-zone architectureRouting and firewall enforcementManagement pathsCloud, OT and restricted networks
Why customers buy this service

Validate that your network segmentation works as designed.

Segmentation fails when the security boundary exists in documentation but routing, NAT, firewall rules, management networks or dual-homed systems create a bypass. It can also fail operationally when a technically strong boundary has no practical support path and is later weakened through exceptions.

Damocles maps the intended trust model and compares it with the effective traffic paths so the customer can see which boundaries are missing, porous or difficult to operate safely.

01

Validate trust zones

Confirm that user, server, management, guest, cloud, OT and restricted networks have the intended access boundaries.

02

Find bypass paths

Identify routing, NAT, dual-homing, management or policy conditions that circumvent the intended control.

03

Design usable segmentation

Balance least privilege with support, monitoring, patching and operational requirements so the control remains maintainable.

What we review

Trust zones, routing domains, firewall boundaries and management paths in the agreed architecture.

The engagement can be focused on one sensitive environment or cover broader enterprise segmentation.

UZ

User zones

Corporate user, wireless, VDI and other user-access networks.

SZ

Server zones

Application, database, infrastructure and shared-service networks.

MZ

Management zones

Administrative, monitoring, backup and infrastructure-management paths.

OT

OT and restricted zones

Operational technology, SCADA, regulated or specially protected networks where applicable.

CL

Cloud connectivity

Cloud routing, private connectivity, VPN and network-security boundaries included in scope.

GP

Guest and third-party access

Guest, vendor, contractor and third-party paths into or across the environment.

Technical assurance

Validate that network segmentation works as designed.

Compare the intended trust model with routing, firewall policy, management access and representative traffic paths to identify missing boundaries and practical bypass paths.

Trust zones

Whether user, server, cloud, OT, guest and restricted environments are separated as intended.

Allowed and denied traffic

Representative permitted and prohibited paths across key boundaries.

Routing and alternate paths

Routes, NAT and alternate forwarding paths that may bypass expected enforcement.

Management access

Administrative paths that cross intended trust boundaries.

Sensitive systems

Whether high-value services are reachable from locations that should not have access.

Exceptions

Temporary or compensating exceptions that weaken the intended model.

Operational usability

Whether monitoring, patching and administration can operate safely.

12governed test areas
3authorised testing perspectives
6controlled evidence outputs
10framework / control evidence mappings
What we actually test

Representative technical coverage with the evidence produced.

These are governed procedures from the service assurance profile—not generic marketing categories. The complete matrix below records applicability, access requirements and limitations for every coverage area.

Jump to full coverage matrix ↓
Coverage area

Trust-zone definition

Damocles maps named systems and services to intended trust zones, data classifications and administrative boundaries.

Evidence producedEvidence records the flow, enforcement point, route, NAT, policy, log or allowed/denied connectivity result relevant to trust-zone definition.
Framework references
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
Coverage area

Permitted boundary flows

Damocles compares the approved flow matrix with representative permitted source, destination, protocol and application paths.

Evidence producedEvidence records the flow, enforcement point, route, NAT, policy, log or allowed/denied connectivity result relevant to permitted boundary flows.
Framework references
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
Coverage area

Rulebase enforcement points

Damocles traces each selected flow through firewall, ACL, host, cloud or identity-aware enforcement points.

Evidence producedEvidence records the flow, enforcement point, route, NAT, policy, log or allowed/denied connectivity result relevant to rulebase enforcement points.
Framework references
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
Coverage area

Routing and alternate paths

Damocles examines routing and alternate paths that could bypass the intended boundary, including asymmetric return traffic.

Evidence producedEvidence records the flow, enforcement point, route, NAT, policy, log or allowed/denied connectivity result relevant to routing and alternate paths.
Framework references
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
Coverage area

NAT effects on segmentation

Damocles accounts for source and destination NAT when correlating observed traffic with segmentation policy.

Evidence producedEvidence records the flow, enforcement point, route, NAT, policy, log or allowed/denied connectivity result relevant to nat effects on segmentation.
Framework references
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
Coverage area

Identity-aware access paths

Damocles tests representative identity-aware decisions using supplied users, devices and expected policy context.

Evidence producedSource-to-destination results linked to rule, route or boundary evidence; the record names the tested identity-aware access paths object, path or control and its observed result.
Framework references
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Showing 6 representative areas. The full governed matrix contains 12 coverage areas.

Standards and assurance coverage

See how this engagement is structured, classified and mapped before opening the full evidence matrix.

References are shown according to the role they play in the engagement. Methodologies guide testing, taxonomies classify findings, severity methods support consistent scoring, and control mappings connect scoped evidence to broader assurance work.

01 · Test method

How testing is structured

Testing is structured by the governed service profile and the procedures expressly included in the authorised scope.

02 · Finding language

How weaknesses and severity are classified

Findings are reported against the governed service coverage and customer impact. Separate classification references are shown only where they are part of the approved profile.

03 · Control evidence

What maps into compliance and assurance work

10governed evidence mappings across 7 approved frameworks and 7 referenced controls.
4 directly assessed2 supporting evidence4 contextual
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0Directly assessed
AC-4

Tests representative information-flow enforcement across selected trust boundaries using approved allowed and denied source-to-destination paths.

Security and Privacy Controls for Information Systems and Organizations Release 5.2.0Directly assessed
SC-7

Reviews selected boundary architecture and enforcement points and validates representative paths across in-scope network boundaries.

Security and Privacy Controls for Information Systems and Organizations Release 5.2.0Supporting evidence
AU-2AU-3

Checks whether sampled boundary decisions produce usable security events with source, destination, protocol, action and policy context where logs are supplied.

+ 7 additional governed mappings in the full control matrix.

Jump to full control mapping ↓
04 · Evidence package

What the customer can use after the engagement

A clear segmentation map, validated traffic-path results, identified bypass conditions and prioritised remediation actions.

  • Authorised scope and rules of engagement
  • Coverage matrix
  • Retest and residual-risk record
  • + 3 additional controlled outputs

What this means: technical evidence may support risk, compliance and audit activity where the mapping is applicable. It does not by itself certify the organisation, establish complete compliance or assess controls outside the authorised scope.

How we test

Manual validation backed by controlled evidence.

Damocles traces intended trust boundaries through routing and enforcement configuration and attempts approved allowed and denied paths from supplied source hosts. A tested path does not establish every possible route; scanning and traffic volume remain within agreed thresholds.

How to read the mapping

Evidence is mapped to the part of a control we can actually assess.

Directly assessed means the engagement tests the relevant behaviour. Supporting evidence means the result can contribute to a broader control assessment. Contextual references explain relevance without claiming that the control was tested.

All relevant frameworks
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0Information Security Manual June 2026Payment Card Industry Data Security Standard 4.0.1Prudential Standard CPS 234 Information Security effective 1 July 2019Prudential Practice Guide CPG 234 Information Security published June 2019ISO/IEC 27001 2022 with Amendment 1:2024ISO/IEC 27002 2022
Testing perspectives3 authorised viewpoints and access models

Source-zone test user or host

Initiates approved allowed and denied traffic from a representative trust zone.

Included when
Used for live boundary validation.
Access required
A source host, identity where required, destination list and protocols.
Limitations
Represents only that source context.

Destination service owner

Confirms the intended consumers, protocols and impact boundaries of sensitive destinations.

Included when
Used to interpret the flow matrix and validation results.
Access required
Service inventory, required flows, owners and test endpoints.
Limitations
Business intent is not proof of enforcement.

Routing and enforcement-point reviewer

Traces routes, ACLs, firewall policy, NAT and identity-aware enforcement across each selected boundary.

Included when
Used for configuration-assisted path analysis.
Access required
Routing tables, policies, NAT, topology and flow matrix.
Limitations
Unseen alternate paths may remain.
Exact test coverage and evidence12 governed coverage areas
What Damocles tests, the evidence produced and the scope boundary for each controlled coverage area.
Coverage areaWhat Damocles testsPerspective and accessEvidence producedReferences and limits
Trust-zone definitionDamocles maps named systems and services to intended trust zones, data classifications and administrative boundaries.Routing and enforcement-point reviewer
Assessment requires trust-zone definitions, flow matrix, routing and policy exports, source hosts and destination test services, selected specifically for trust-zone definition.
Evidence records the flow, enforcement point, route, NAT, policy, log or allowed/denied connectivity result relevant to trust-zone definition.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Trust-zone definition when the boundary and representative source and destination are authorised.

Limit: The conclusion is limited to the sampled trust-zone definition; only sampled paths are established; scanning volume and excluded zones remain bounded.

Permitted boundary flowsDamocles compares the approved flow matrix with representative permitted source, destination, protocol and application paths.Source-zone test user or host
Assessment requires trust-zone definitions, flow matrix, routing and policy exports, source hosts and destination test services, selected specifically for permitted boundary flows.
Evidence records the flow, enforcement point, route, NAT, policy, log or allowed/denied connectivity result relevant to permitted boundary flows.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Permitted boundary flows when the boundary and representative source and destination are authorised.

Limit: The conclusion is limited to the sampled permitted boundary flows; only sampled paths are established; scanning volume and excluded zones remain bounded.

Rulebase enforcement pointsDamocles traces each selected flow through firewall, ACL, host, cloud or identity-aware enforcement points.Routing and enforcement-point reviewer
Assessment requires trust-zone definitions, flow matrix, routing and policy exports, source hosts and destination test services, selected specifically for rulebase enforcement points.
Evidence records the flow, enforcement point, route, NAT, policy, log or allowed/denied connectivity result relevant to rulebase enforcement points.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Rulebase enforcement points when the boundary and representative source and destination are authorised.

Limit: The conclusion is limited to the sampled rulebase enforcement points; only sampled paths are established; scanning volume and excluded zones remain bounded.

Routing and alternate pathsDamocles examines routing and alternate paths that could bypass the intended boundary, including asymmetric return traffic.Routing and enforcement-point reviewer
Assessment requires trust-zone definitions, flow matrix, routing and policy exports, source hosts and destination test services, selected specifically for routing and alternate paths.
Evidence records the flow, enforcement point, route, NAT, policy, log or allowed/denied connectivity result relevant to routing and alternate paths.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Routing and alternate paths when the boundary and representative source and destination are authorised.

Limit: The conclusion is limited to the sampled routing and alternate paths; only sampled paths are established; scanning volume and excluded zones remain bounded.

NAT effects on segmentationDamocles accounts for source and destination NAT when correlating observed traffic with segmentation policy.Source-zone test user or host
Assessment requires trust-zone definitions, flow matrix, routing and policy exports, source hosts and destination test services, selected specifically for nat effects on segmentation.
Evidence records the flow, enforcement point, route, NAT, policy, log or allowed/denied connectivity result relevant to nat effects on segmentation.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to NAT effects on segmentation when the boundary and representative source and destination are authorised.

Limit: The conclusion is limited to the sampled nat effects on segmentation; only sampled paths are established; scanning volume and excluded zones remain bounded.

Identity-aware access pathsDamocles tests representative identity-aware decisions using supplied users, devices and expected policy context.Destination service owner
Named source and destination test points, expected flow matrix and a safe test window; customer inputs must identify the approved identity-aware access paths targets and expected behaviour.
Source-to-destination results linked to rule, route or boundary evidence; the record names the tested identity-aware access paths object, path or control and its observed result.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Performed when representative identities and the corresponding permission or ownership boundary are included in scope.

Limit: Conclusions cover only the supplied identities, roles and records; credential guessing, lockout and privileged changes stop at the agreed thresholds.

East-west administrative protocolsDamocles attempts approved east-west management protocols between representative zones and records allowed and denied outcomes.Source-zone test user or host
Current configuration export or read-only access, diagrams, owners and representative validation endpoints.
Configuration excerpts, object or rule identifiers and observed validation results.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Performed when current configuration evidence and a representative endpoint or device are included in the review.

Limit: A configuration snapshot cannot prove continuous enforcement across excluded nodes; validation avoids changes unless implementation work is authorised.

Representative path validationDamocles sends approved test traffic from actual source hosts to destination services and records the enforcement point and result.Source-zone test user or host
Named source and destination test points, expected flow matrix and a safe test window.
Source-to-destination results linked to rule, route or boundary evidence; the record names the tested representative path validation object, path or control and its observed result.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Performed when both ends of the network path and the enforcing device are owned or expressly authorised for testing.

Limit: Results cover the tested source, destination, protocol and route; testing stops on instability and does not authorise third-party or denial-of-service activity.

Sensitive-zone reachabilityDamocles tests named high-value destinations and forbidden protocols from representative lower-trust zones.Source-zone test user or host
Named source and destination test points, expected flow matrix and a safe test window.
Source-to-destination results linked to rule, route or boundary evidence; the record names the tested sensitive-zone reachability object, path or control and its observed result.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Performed when both ends of the network path and the enforcing device are owned or expressly authorised for testing.

Limit: Results cover the tested source, destination, protocol and route; testing stops on instability and does not authorise third-party or denial-of-service activity.

Logging at boundariesDamocles confirms whether boundary decisions create usable logs with source, destination, protocol, action and policy identity.Routing and enforcement-point reviewer
Log-source inventory, representative event identifiers, workflow records and responsible contacts.
Source-health state, event timestamps, investigation timeline and linked action or escalation record.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Performed when the relevant telemetry and analyst or customer workflow can be observed during the review window.

Limit: Absent or delayed telemetry prevents a detection conclusion, and observation of one event cannot prove continuous detection of all attacks.

Third-party and remote accessDamocles traces third-party and remote-access routes into internal zones and compares them with intended access restrictions.Destination service owner
Assessment requires trust-zone definitions, flow matrix, routing and policy exports, source hosts and destination test services, selected specifically for third-party and remote access.
Evidence records the flow, enforcement point, route, NAT, policy, log or allowed/denied connectivity result relevant to third-party and remote access.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Third-party and remote access when the boundary and representative source and destination are authorised.

Limit: The conclusion is limited to the sampled third-party and remote access; only sampled paths are established; scanning volume and excluded zones remain bounded.

Exceptions and compensating controlsDamocles records segmentation exceptions, owners, expiry, compensating controls and validation evidence.Source-zone test user or host
Assessment requires trust-zone definitions, flow matrix, routing and policy exports, source hosts and destination test services, selected specifically for exceptions and compensating controls.
Evidence records the flow, enforcement point, route, NAT, policy, log or allowed/denied connectivity result relevant to exceptions and compensating controls.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Exceptions and compensating controls when the boundary and representative source and destination are authorised.

Limit: The conclusion is limited to the sampled exceptions and compensating controls; only sampled paths are established; scanning volume and excluded zones remain bounded.

Framework and control mappings10 governed evidence mappings
Where scoped technical evidence maps to approved security frameworks and control objectives.
Framework and controlsMapping typeWhat Damocles assessesEvidence producedApplicability and limits
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
AC-4
Directly assessedTests representative information-flow enforcement across selected trust boundaries using approved allowed and denied source-to-destination paths.Expected flow matrix, source and destination context, enforcement-point evidence and observed connectivity results.

Applies: Applies where representative trust zones, test hosts, destinations and expected flows are included.

Limit: Only sampled paths are established; alternate routes, excluded zones and unsampled protocols remain outside the conclusion.

Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
SC-7
Directly assessedReviews selected boundary architecture and enforcement points and validates representative paths across in-scope network boundaries.Trust-zone and enforcement map, routes, firewall or ACL evidence, alternate-path observations and validated boundary results.

Applies: Applies to selected network boundaries and enforcement points within the authorised segmentation scope.

Limit: Does not establish every network boundary, route, enforcement point or continuous boundary operation.

Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
AU-2AU-3
Supporting evidenceChecks whether sampled boundary decisions produce usable security events with source, destination, protocol, action and policy context where logs are supplied.Generated or observed test flows correlated to supplied boundary event records.

Applies: Applies only where relevant boundary logging is included and accessible.

Limit: Does not establish complete logging policy, event content, retention, analysis or continuous monitoring coverage.

Information Security Manual June 2026
ISM-1181
Directly assessedTests representative segregation between customer-defined network zones according to the supplied trust model and expected flow matrix.Trust-zone map, approved source and destination test points, observed allowed and denied traffic results and enforcement evidence.

Applies: Applies where the organisation has defined network zones and representative paths are included for validation.

Limit: Testing proves only sampled zone relationships and does not establish that every network segment or path satisfies ISM-1181.

Information Security Manual June 2026
ISM-0631
Directly assessedWhere an in-scope boundary uses a gateway, tests whether representative gateway paths permit only explicitly authorised flows from the approved flow matrix.Gateway policy identifiers, expected flow matrix and observed allowed or denied connectivity results.

Applies: Applies only to selected gateway-enforced boundaries with representative test points and authorised flow expectations.

Limit: Does not establish every gateway data flow, non-gateway boundary or continuous conformity with ISM-0631.

Prudential Standard CPS 234 Information Security effective 1 July 2019
CPS 234 paragraph 27
Supporting evidenceProduces scoped network segmentation-review evidence that may support an APRA-regulated entity's systematic testing of information-security control effectiveness.Governed scope, trust-zone and enforcement evidence, sampled path results, findings, remediation guidance and retest results where included.

Applies: Relevant only where the customer determines that the assessed segmentation controls and evidence are applicable to its assurance or compliance scope. For APRA-regulated entities, the customer determines how the engagement contributes to its broader systematic control-testing program.

Limit: A scoped engagement does not by itself establish the customer's systematic testing program, testing frequency, full control population, specialist independence, governance, reporting or compliance with other CPS 234 requirements.

Prudential Practice Guide CPG 234 Information Security published June 2019
Framework-level context
ContextualProduces scoped network segmentation-review evidence consistent with CPG 234 guidance that testing techniques should be selected for the control and risk being assessed.Governed scope, trust-zone and enforcement evidence, sampled path results, findings, remediation guidance and retest results where included.

Applies: Relevant only where the customer determines that the assessed segmentation controls and evidence are applicable to its assurance or compliance scope. APRA-regulated customers determine how this evidence contributes to their broader assurance program.

Limit: CPG 234 is prudential guidance rather than a standalone certification target; this mapping does not claim assessment of the complete guidance or customer compliance.

ISO/IEC 27001 2022 with Amendment 1:2024
Framework-level context
ContextualProduces scoped network segmentation-review evidence that may support customer assurance activities organised around ISO/IEC 27001 where the assessed systems and behaviours are relevant.Governed scope, trust-zone and enforcement evidence, sampled path results, findings, remediation guidance and retest results where included.

Applies: Relevant only where the customer determines that the assessed segmentation controls and evidence are applicable to its assurance or compliance scope.

Limit: Licensed ISO/IEC 27001 control or requirement identifiers and text are intentionally withheld. The engagement does not establish ISO/IEC 27001 certification, attestation or whole-framework conformity.

ISO/IEC 27002 2022
Framework-level context
ContextualProduces scoped network segmentation-review evidence that may support customer assurance activities organised around ISO/IEC 27002 where the assessed systems and behaviours are relevant.Governed scope, trust-zone and enforcement evidence, sampled path results, findings, remediation guidance and retest results where included.

Applies: Relevant only where the customer determines that the assessed segmentation controls and evidence are applicable to its assurance or compliance scope.

Limit: Licensed ISO/IEC 27002 control or requirement identifiers and text are intentionally withheld. The engagement does not establish ISO/IEC 27002 certification, attestation or whole-framework conformity.

Payment Card Industry Data Security Standard 4.0.1
Framework-level context
ContextualProduces scoped network segmentation-review evidence that may support customer assurance activities organised around PCI DSS where the assessed systems and behaviours are relevant.Governed scope, trust-zone and enforcement evidence, sampled path results, findings, remediation guidance and retest results where included.

Applies: Relevant only where the customer determines that the assessed segmentation controls and evidence are applicable to its assurance or compliance scope.

Limit: Licensed PCI DSS control or requirement identifiers and text are intentionally withheld. The engagement does not establish PCI DSS certification, attestation or whole-framework conformity.

Assurance boundary: Damocles maps assessed coverage and observations to agreed objectives as traceable technical evidence. The review is not a certification, does not establish complete compliance, and does not confirm controls outside the authorised scope.

Report and evidence outputs6 controlled output types

Authorised scope and rules of engagement

Records authorised scope and rules of engagement produced from the authorised Network segmentation review work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Coverage matrix

Records coverage matrix produced from the authorised Network segmentation review work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Retest and residual-risk record

Records retest and residual-risk record produced from the authorised Network segmentation review work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Trust-zone and enforcement map

Records trust-zone and enforcement map produced from the authorised Network segmentation review work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Allowed and denied path results

Records allowed and denied path results produced from the authorised Network segmentation review work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Segmentation exception register

Records segmentation exception register produced from the authorised Network segmentation review work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.
What you receive

A clear segmentation map, validated traffic-path results, identified bypass conditions and prioritised remediation actions.

What we commonly find

Segmentation weaknesses that create lateral movement or operational pressure to weaken controls.

The review looks at both technical bypass and control designs that are unlikely to survive day-to-day operations.

BR

Boundary bypass

Routing, NAT, direct links or dual-homing that circumvent the intended enforcement point.

BA

Broad zone access

Large network-to-network rules that provide more reach than the application or support requirement.

MG

Management crossover

Administrative and infrastructure-management paths shared with lower-trust networks.

OT

OT exposure

Paths between business IT, remote access, management and operational networks beyond the intended model.

EX

Exception creep

Temporary rules and support exceptions that gradually erode the segmentation boundary.

OP

Operationally unusable design

A boundary that blocks necessary monitoring, patching, backup or support and therefore encourages insecure workarounds.

Engagement options

Choose the sensitive environment or segmentation program that needs assurance.

The scope identifies zones, routers, firewalls, cloud networks, critical applications and management dependencies.

Focused
OT

OT/SCADA segmentation review

Review business-to-OT, management, vendor and security-tool access around operational networks.

Data centre
DC

Data-centre segmentation review

Review application, database, management and shared-service boundaries and east-west access.

Cloud
CL

Hybrid/cloud segmentation review

Review on-premises-to-cloud and cloud-internal routing and enforcement boundaries.

Enterprise
EN

Enterprise segmentation program

Map and redesign broader trust zones across sites, data centres and cloud environments.

What you receive

A segmentation model tied to the actual routes and enforcement points that make it real.

Outputs are suitable for security architecture and the network engineers who must implement the boundary.

CM

Current-state segmentation map

Trust zones, routing domains, enforcement points and major cross-zone dependencies.

BF

Boundary findings

Unintended paths, broad access, management crossover and bypass conditions.

TF

Traffic-flow requirements

Required application and support flows used to distinguish legitimate access from excess reach.

TA

Target segmentation model

Recommended trust zones, enforcement locations and access principles where redesign is included.

CP

Change priorities

Sequenced changes based on risk, application dependency and operational complexity.

VR

Validation approach

Traffic and access tests required to prove intended communication works and prohibited paths are blocked.

Implementation and remediation

Damocles can separately scope firewall, routing and network changes required to implement the target segmentation.

Implementation work identifies the affected firewalls, routers, security groups, routes, NAT, maintenance windows, application owners and rollback approach before production change.

Post-change validation checks both permitted business traffic and the boundaries the project was intended to enforce.

Scope boundaries

The review is based on the agreed architecture, devices and traffic dependencies provided or discovered during scope.

Full application dependency mapping, host hardening and endpoint security are separate services unless included because they are required to validate the segmentation design.

A design recommendation does not imply implementation unless production change is explicitly scoped.

Scope the service

Tell us the environments that must be separated and the applications that still need to communicate.

We will scope the zones, routing, enforcement points, dependency information, target design and implementation support required.